CVE-1999-1476: Low severity Intel Pentuim vulnerability
A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the "Invalid Operand with Locked CMPXCHG8B Instruction" problem.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict local untrusted access to systems running on affected Intel Pentium processors. Steps include limiting or removing unnecessary local user accounts, enforcing least-privilege for local accounts, restricting interactive or physical logons to trusted personnel, and preventing execution of untrusted local code. Monitor vendor advisories and apply any OS/vendor-issued patches or mitigations when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1476?
CVE-1999-1476 has a high severity level as it can lead to a denial of service on affected Intel processors.
How do I fix CVE-1999-1476?
To mitigate CVE-1999-1476, users should avoid using the vulnerable Intel Pentium processors and upgrade to a newer model.
Which systems are impacted by CVE-1999-1476?
CVE-1999-1476 affects Intel-based operating systems like Windows NT and Windows 95.
Who is affected by CVE-1999-1476?
Local users on systems using Intel Pentium (MMX and Overdrive) processors are affected by CVE-1999-1476.
What causes the issues in CVE-1999-1476?
The issues in CVE-1999-1476 are caused by an invalid instruction related to the Locked CMPXCHG8B instruction in Intel Pentium processors.