CVE-2017-5925: Infoleak
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5925?
CVE-2017-5925 is considered a high-severity vulnerability as it allows unauthorized data leakage through side-channel attacks.
How do I fix CVE-2017-5925?
Fixing CVE-2017-5925 involves applying relevant software patches or firmware updates provided by the affected hardware manufacturers.
What systems are affected by CVE-2017-5925?
CVE-2017-5925 affects a range of systems including various Intel, AMD, and Nvidia processors.
What type of attack is CVE-2017-5925 associated with?
CVE-2017-5925 is associated with side-channel attacks exploiting MMU operations during virtual to physical address translations.
How does CVE-2017-5925 impact security measures like ASLR?
CVE-2017-5925 undermines ASLR by enabling attackers to leak memory addresses and pointers, potentially leading to further exploitations.