CVE-2018-12126

Advisory lineage Upstream: 0 Downstream: 126
Modified
Published: 30 May 2019, 15:36
Last modified:29 May 2026, 20:09

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.6 MEDIUM
v3.1 (nvd)
EPSS Score
0.52% LOW
1% probability +0.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 May 2019, 15:36
Published
Vulnerability first disclosed
29 May 2026, 20:09
Last Modified
Vulnerability information updated

Description

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v3.0MEDIUMScore: 5.6CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.7AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS Trends

Current EPSS score: 0.52% Percentile: 67%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • fedoraprojectfedora

    29

  • intel corporationcentral proccve-2018-12126essing units (cpus)

    A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

  • intelmicroarchitectural_store_buffer_data_sampling_firmware

    na

References (25)