CVE-2017-5925 describes a side-channel vulnerability in the Memory Management Unit (MMU) of modern Intel processors, affecting various vendors including Allwinner, AMD, Intel, Nvidia, and Samsung. This flaw allows an attacker to leak data and code pointers from JavaScript by observing cache traces left during virtual-to-physical address translation, effectively bypassing Address Space Layout Randomization (ASLR). Rated 7.5 HIGH, it presents a high confidentiality impact with low attack complexity, requiring no user interaction or privileges. While the vulnerability has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:allwinner:a64:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:athlon_ii_640_x4:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:e-350:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:fx-8120_8-core:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:fx-8320_8-core:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.