CVE-2018-12127

Advisory lineage Upstream: 0 Downstream: 123
Modified
Published: 30 May 2019, 15:38
Last modified:29 May 2026, 20:09

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.6 MEDIUM
v3.1 (nvd)
EPSS Score
0.52% LOW
1% probability +0.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 May 2019, 15:38
Published
Vulnerability first disclosed
29 May 2026, 20:09
Last Modified
Vulnerability information updated

Description

Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v3.0MEDIUMScore: 5.6CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.7AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS Trends

Current EPSS score: 0.52% Percentile: 67%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • fedoraprojectfedora

    29

  • intel corporationcentral processing units (cpus)

    A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

  • intelmicroarchitectural_load_port_data_sampling_firmware

    na

References (25)