CVE-2018-12207

MEDIUM

Intel Core i3 Firmware - Authenticated Denial of Service via Page Table Update Invalidation

Title source: llm
STIX 2.1

Description

Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.

References (16)

Core 16
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3916
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3936
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3941
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4186-2/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2020:0026
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2020:0028
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4602
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2020/Jan/21
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2020:0204
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202003-56
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 49.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (50)
canonical/ubuntu_linux 14.04
debian/debian_linux 9.0
f5/big-ip_access_policy_manager 11.5.2 - 11.6.5
f5/big-ip_advanced_firewall_manager 11.5.2 - 11.6.5
f5/big-ip_analytics 11.5.2 - 11.6.5
f5/big-ip_application_acceleration_manager 11.5.2 - 11.6.5
f5/big-ip_application_security_manager 11.5.2 - 11.6.5
f5/big-ip_domain_name_system 11.5.2 - 11.6.5
f5/big-ip_fraud_protection_service 11.5.2 - 11.6.5
f5/big-ip_global_traffic_manager 11.5.2 - 11.6.5
... and 40 more
Published Nov 14, 2019
Tracked Since Feb 18, 2026