CVE-2024-7881CWE-1422

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an…

Medium · published January 28, 2025

CVSS v3.1
5.1
EPSS
0%
Percentile
9.4
In the wild
Unconfirmed
What it is

An unprivileged context can trigger a data

memory-dependent prefetch engine to fetch the contents of a privileged location

and consume those contents as an address that is also dereferenced.

The record
Technical detail
CVSS v3.1
5.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00196 · 9.4th percentile
Weakness
CWE-1422 · Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
Published
2025-01-28T15:01Z
EPSS history
Timeline
  • 28 JAN 15:01Z
    An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an…
    cvelistv5