VDB
CNVD-2018-00303
CNVD-2018-00303
PUBLISHED
CVSS 9.300000190734863 CRITICAL
CPU hardware是一套运行在CPU(中央处理器)中用于管理和控制CPU的固件。 CPU处理器内核存在Spectre漏洞,由于Intel未将低权限的应用程序与访问内核内存分开,导致攻击者可以使用恶意应用程序来获取应该被隔离的私有数据。
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cnvd | VMWare ESXi 6.5 | |
| Microsoft Windows 10 for x64-based Systems | ||
| cnvd | Microsoft Windows 10 version 1511 for 32-bit Systems 0 | |
| cnvd | Red Hat Enterprise Linux Server AUS 7.4 | |
| cnvd | VMWare Fusion 8.5.8 | |
| VMWare Workstation 12.5.7 | ||
| Red Hat Enterprise Linux 6 | ||
| Red Hat Enterprise Linux Desktop 6 | ||
| Red Hat Enterprise Linux Server AUS 6.6 | ||
| cnvd | Microsoft Windows 10 Version 1703 for x64-based Systems | |
| Cisco vBond Orchestrator | ||
| Red Hat Enterprise Linux Server AUS 7.2 | ||
| Red Hat Enterprise Linux Server 7 | ||
| cnvd | Microsoft Windows Server 2008 R2 | |
| cnvd | Microsoft Internet Explorer 11 | |
| Microsoft Windows 10 for 32-bit Systems | ||
| cnvd | Microsoft Windows 10 for x64-based Systems | |
| cnvd | Microsoft Windows Server 2016 | |
| cnvd | Microsoft Windows 10 Version 1703 for 32-bit Systems | |
| Apple IOS <11.2 |
…and 110 more
Timeline
- Jan 4, 2018 CVE ID Reserved
- Jan 4, 2018 CVE Published