CVE-2018-12207
Last modified
CVE-2018-12207 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Core I3-10110u Firmware | All versions |
| Intel | Core I3-10110y Firmware | All versions |
| Intel | Core I3-1005g1 Firmware | All versions |
| Intel | Core I3-9300t Firmware | All versions |
| Intel | Core I3-9300 Firmware | All versions |
| Intel | Core I3-9100 Firmware | All versions |
| Intel | Core I3-9100t Firmware | All versions |
| Intel | Core I3-9350k Firmware | All versions |
| Intel | Core I3-9320 Firmware | All versions |
| Intel | Core I3-8145u Firmware | All versions |
| Intel | Core I3-8300 Firmware | All versions |
| Intel | Core I3-8100t Firmware | All versions |
| Intel | Core I3-8300t Firmware | All versions |
| Intel | Core I3-8109u Firmware | All versions |
| Intel | Core I3-8130u Firmware | All versions |
| Intel | Core I3-8100 Firmware | All versions |
| Intel | Core I3-8350k Firmware | All versions |
| Intel | Core I3-7100 Firmware | All versions |
| Intel | Core I3-7350k Firmware | All versions |
| Intel | Core I3-7300t Firmware | All versions |
| Intel | Core I3-7167u Firmware | All versions |
| Intel | Core I3-7300 Firmware | All versions |
| Intel | Core I3-7100h Firmware | All versions |
| Intel | Core I3-7320 Firmware | All versions |
| Intel | Core I3-7100t Firmware | All versions |
| Intel | Core I3-7100u Firmware | All versions |
| Intel | Core I3-6100u Firmware | All versions |
| Intel | Core I3-6100h Firmware | All versions |
| Intel | Core I3-6167u Firmware | All versions |
| Intel | Core I3-6100 Firmware | All versions |
| Intel | Core I3-5015u Firmware | All versions |
| Intel | Core I3-5020u Firmware | All versions |
| Intel | Core I3-5005u Firmware | All versions |
| Intel | Core I3-5010u Firmware | All versions |
| Intel | Core I3-5157u Firmware | All versions |
| Intel | Core I5-10210u Firmware | All versions |
| Intel | Core I5-10310y Firmware | All versions |
| Intel | Core I5-10210y Firmware | All versions |
| Intel | Core I5-1035g4 Firmware | All versions |
| Intel | Core I5-1035g7 Firmware | All versions |
| Intel | Core I5-1035g1 Firmware | All versions |
| Intel | Core I5-9500 Firmware | All versions |
| Intel | Core I5-9600 Firmware | All versions |
| Intel | Core I5-9400t Firmware | All versions |
| Intel | Core I5-9600t Firmware | All versions |
| Intel | Core I5-9500t Firmware | All versions |
| Intel | Core I5-9300h Firmware | All versions |
| Intel | Core I5-9400h Firmware | All versions |
| Intel | Core I5-9400 Firmware | All versions |
| Intel | Core I5-9600k Firmware | All versions |
Showing 50 of 830 affected configurations. See NVD for the full list.
References
- https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3916Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3941Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0026Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0028Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0204Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/21Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-56Third Party Advisory
- https://usn.ubuntu.com/4186-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4602Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3916Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3941Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0026Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0028Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0204Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/21Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-56Third Party Advisory
- https://usn.ubuntu.com/4186-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4602Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12207?
How severe is CVE-2018-12207?
How do I fix CVE-2018-12207?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12201Buffer overflow vulnerability in Platform Sample / Silicon R…
- CVE-2018-12202Privilege escalation vulnerability in Platform Sample/ Silic…
- CVE-2018-12203Denial of service vulnerability in Platform Sample/ Silicon …
- CVE-2018-12204Improper memory initialization in Platform Sample/Silicon Re…
- CVE-2018-12205Improper certificate validation in Platform Sample/ Silicon …
- CVE-2018-12206Improper configuration of hardware access in Intel QuickAssi…
- CVE-2018-12208Buffer overflow in HECI subsystem in Intel(R) CSME before ve…
- CVE-2018-12209Insufficient access control in User Mode Driver in Intel(R) …
- CVE-2018-1221In cf-deployment before 1.14.0 and routing-release before 0.…8.1
- CVE-2018-12210Multiple pointer dereferences in User Mode Driver in Intel(R…
- CVE-2018-12211Insufficient input validation in User Mode Driver in Intel(R…
- CVE-2018-12212Buffer overflow in User Mode Driver in Intel(R) Graphics Dri…
Are you affected by CVE-2018-12207?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
