
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2023-38575) was discovered in Intel Processors involving non-transparent sharing of return predictor targets between contexts. This vulnerability was publicly disclosed on March 12, 2024, affecting various Intel Processor models. The vulnerability allows an authorized user to potentially enable information disclosure through local access (Intel Advisory, NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium), with a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. This indicates that the vulnerability requires local access, low attack complexity, and low privileges, with no user interaction needed. The scope is unchanged, and the impact is limited to high confidentiality breach with no impact on integrity or availability. The vulnerability is classified under CWE-1303 (Non-Transparent Sharing of Microarchitectural Resources) (Intel Advisory, Red Hat).
The vulnerability can lead to information disclosure, potentially impacting the data confidentiality of the targeted host. When successfully exploited, it allows an authorized user to access sensitive information through local access. The high confidentiality impact suggests that the attacker could gain access to significant amounts of sensitive data (Red Hat).
The vulnerability requires local access to the system and low privileges for exploitation. The attack complexity is rated as low, indicating that the attack can be performed with minimal conditions that need to be satisfied for exploitation. No user interaction is required for the exploit to succeed (Intel Advisory).
Intel has released microcode updates to mitigate this vulnerability. Users of affected Intel Processors are recommended to update to the latest version firmware provided by their system manufacturer. For non-Intel Software Guard Extension (SGX) customers, the microcode patch can be OS loadable. For Intel SGX enabled systems, Intel recommends updating the microcode located in platform flash designated by firmware interface table (FIT) entry point1 (Intel Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."