CVE-2017-5753

Exp

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

Published: 2018-01-04 Last update: 2026-05-28 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2017-5753 is rated High Exploit Risk (71.8/100): CVSS Medium severity, with high exploitation likelihood (EPSS 93.84%, 100th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2017-5753

EDB-ID Source Kind Published Link
43427 exploit_db edb 2018-01-03 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2017-5753

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 94.33% 93.84% -0.49%
2 2025-11-21 92.99% 94.33% +1.35%
3 2025-11-18 92.99%

Full EPSS history (19 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2017-5753

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.6 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.1 4.0 [email protected]
5.6 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.1 4.0 134c704f-9b21-4f2e-91b3-4a467353bcc0
4.7 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.4 6.9 [email protected]

Weakness enumeration for CVE-2017-5753

OS Trackers for CVE-2017-5753

vendor priority summary link
alpine CVE-2017-5753: 1 source package rows (intel-ucode); 7 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 0. https://security.alpinelinux.org/vuln/CVE-2017-5753
debian not yet assigned CVE-2017-5753 not yet assigned priority: Debian including 3 source packages (linux, nvidia-graphics-drivers, nvidia-graphics-drivers-legacy-340xx), 11 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 11. https://security-tracker.debian.org/tracker/CVE-2017-5753
gentoo normal CVE-2017-5753: 1 GLSA(s) (201810-06), 2 atom(s) (app-emulation/xen, app-emulation/xen-tools); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2017-5753
redhat high https://access.redhat.com/security/cve/CVE-2017-5753
suse high https://www.suse.com/security/cve/CVE-2017-5753/
ubuntu high CVE-2017-5753 high priority: Ubuntu including 83 source packages (firefox, linux, …), 722 status rows across 12 suites (artful, bionic, cosmic, disco, focal, jammy, noble, oracular, trusty, upstream, xenial, zesty): DNE 454, not-affected 137, released 116, ignored 14, needs-triage 1. https://ubuntu.com/security/CVE-2017-5753

Affected software / configurations for CVE-2017-5753

Vendor Product Version Raw CPE
intel atom_c c2308 cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*
intel atom_c c2316 cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:*
intel atom_c c2338 cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:*
intel atom_c c2350 cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:*
intel atom_c c2358 cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:*
intel atom_c c2508 cpe:2.3:h:intel:atom_c:c2508:*:*:*:*:*:*:*
intel atom_c c2516 cpe:2.3:h:intel:atom_c:c2516:*:*:*:*:*:*:*
intel atom_c c2518 cpe:2.3:h:intel:atom_c:c2518:*:*:*:*:*:*:*
intel atom_c c2530 cpe:2.3:h:intel:atom_c:c2530:*:*:*:*:*:*:*
intel atom_c c2538 cpe:2.3:h:intel:atom_c:c2538:*:*:*:*:*:*:*
intel atom_c c2550 cpe:2.3:h:intel:atom_c:c2550:*:*:*:*:*:*:*
intel atom_c c2558 cpe:2.3:h:intel:atom_c:c2558:*:*:*:*:*:*:*
intel atom_c c2718 cpe:2.3:h:intel:atom_c:c2718:*:*:*:*:*:*:*
intel atom_c c2730 cpe:2.3:h:intel:atom_c:c2730:*:*:*:*:*:*:*
intel atom_c c2738 cpe:2.3:h:intel:atom_c:c2738:*:*:*:*:*:*:*
intel atom_c c2750 cpe:2.3:h:intel:atom_c:c2750:*:*:*:*:*:*:*
intel atom_c c2758 cpe:2.3:h:intel:atom_c:c2758:*:*:*:*:*:*:*
intel atom_c c3308 cpe:2.3:h:intel:atom_c:c3308:*:*:*:*:*:*:*
intel atom_c c3338 cpe:2.3:h:intel:atom_c:c3338:*:*:*:*:*:*:*
intel atom_c c3508 cpe:2.3:h:intel:atom_c:c3508:*:*:*:*:*:*:*
intel atom_c c3538 cpe:2.3:h:intel:atom_c:c3538:*:*:*:*:*:*:*
intel atom_c c3558 cpe:2.3:h:intel:atom_c:c3558:*:*:*:*:*:*:*
intel atom_c c3708 cpe:2.3:h:intel:atom_c:c3708:*:*:*:*:*:*:*
intel atom_c c3750 cpe:2.3:h:intel:atom_c:c3750:*:*:*:*:*:*:*
intel atom_c c3758 cpe:2.3:h:intel:atom_c:c3758:*:*:*:*:*:*:*
intel atom_c c3808 cpe:2.3:h:intel:atom_c:c3808:*:*:*:*:*:*:*
intel atom_c c3830 cpe:2.3:h:intel:atom_c:c3830:*:*:*:*:*:*:*
intel atom_c c3850 cpe:2.3:h:intel:atom_c:c3850:*:*:*:*:*:*:*
intel atom_c c3858 cpe:2.3:h:intel:atom_c:c3858:*:*:*:*:*:*:*
intel atom_c c3950 cpe:2.3:h:intel:atom_c:c3950:*:*:*:*:*:*:*
intel atom_c c3955 cpe:2.3:h:intel:atom_c:c3955:*:*:*:*:*:*:*
intel atom_c c3958 cpe:2.3:h:intel:atom_c:c3958:*:*:*:*:*:*:*
intel atom_e e3805 cpe:2.3:h:intel:atom_e:e3805:*:*:*:*:*:*:*
intel atom_e e3815 cpe:2.3:h:intel:atom_e:e3815:*:*:*:*:*:*:*
intel atom_e e3825 cpe:2.3:h:intel:atom_e:e3825:*:*:*:*:*:*:*
intel atom_e e3826 cpe:2.3:h:intel:atom_e:e3826:*:*:*:*:*:*:*
intel atom_e e3827 cpe:2.3:h:intel:atom_e:e3827:*:*:*:*:*:*:*
intel atom_e e3845 cpe:2.3:h:intel:atom_e:e3845:*:*:*:*:*:*:*
intel atom_x3 c3130 cpe:2.3:h:intel:atom_x3:c3130:*:*:*:*:*:*:*
intel atom_x3 c3200rk cpe:2.3:h:intel:atom_x3:c3200rk:*:*:*:*:*:*:*
intel atom_x3 c3205rk cpe:2.3:h:intel:atom_x3:c3205rk:*:*:*:*:*:*:*
intel atom_x3 c3230rk cpe:2.3:h:intel:atom_x3:c3230rk:*:*:*:*:*:*:*
intel atom_x3 c3235rk cpe:2.3:h:intel:atom_x3:c3235rk:*:*:*:*:*:*:*
intel atom_x3 c3265rk cpe:2.3:h:intel:atom_x3:c3265rk:*:*:*:*:*:*:*
intel atom_x3 c3295rk cpe:2.3:h:intel:atom_x3:c3295rk:*:*:*:*:*:*:*
intel atom_x3 c3405 cpe:2.3:h:intel:atom_x3:c3405:*:*:*:*:*:*:*
intel atom_x3 c3445 cpe:2.3:h:intel:atom_x3:c3445:*:*:*:*:*:*:*
intel atom_x5-e3930 cpe:2.3:h:intel:atom_x5-e3930:-:*:*:*:*:*:*:*
intel atom_x5-e3940 cpe:2.3:h:intel:atom_x5-e3940:-:*:*:*:*:*:*:*
intel atom_x7-e3950 cpe:2.3:h:intel:atom_x7-e3950:-:*:*:*:*:*:*:*
intel atom_z z2420 cpe:2.3:h:intel:atom_z:z2420:*:*:*:*:*:*:*
intel atom_z z2460 cpe:2.3:h:intel:atom_z:z2460:*:*:*:*:*:*:*
intel atom_z z2480 cpe:2.3:h:intel:atom_z:z2480:*:*:*:*:*:*:*
intel atom_z z2520 cpe:2.3:h:intel:atom_z:z2520:*:*:*:*:*:*:*
intel atom_z z2560 cpe:2.3:h:intel:atom_z:z2560:*:*:*:*:*:*:*
intel atom_z z2580 cpe:2.3:h:intel:atom_z:z2580:*:*:*:*:*:*:*
intel atom_z z2760 cpe:2.3:h:intel:atom_z:z2760:*:*:*:*:*:*:*
intel atom_z z3460 cpe:2.3:h:intel:atom_z:z3460:*:*:*:*:*:*:*
intel atom_z z3480 cpe:2.3:h:intel:atom_z:z3480:*:*:*:*:*:*:*
intel atom_z z3530 cpe:2.3:h:intel:atom_z:z3530:*:*:*:*:*:*:*
intel atom_z z3560 cpe:2.3:h:intel:atom_z:z3560:*:*:*:*:*:*:*
intel atom_z z3570 cpe:2.3:h:intel:atom_z:z3570:*:*:*:*:*:*:*
intel atom_z z3580 cpe:2.3:h:intel:atom_z:z3580:*:*:*:*:*:*:*
intel atom_z z3590 cpe:2.3:h:intel:atom_z:z3590:*:*:*:*:*:*:*
intel atom_z z3735d cpe:2.3:h:intel:atom_z:z3735d:*:*:*:*:*:*:*
intel atom_z z3735e cpe:2.3:h:intel:atom_z:z3735e:*:*:*:*:*:*:*
intel atom_z z3735f cpe:2.3:h:intel:atom_z:z3735f:*:*:*:*:*:*:*
intel atom_z z3735g cpe:2.3:h:intel:atom_z:z3735g:*:*:*:*:*:*:*
intel atom_z z3736f cpe:2.3:h:intel:atom_z:z3736f:*:*:*:*:*:*:*
intel atom_z z3736g cpe:2.3:h:intel:atom_z:z3736g:*:*:*:*:*:*:*
intel atom_z z3740 cpe:2.3:h:intel:atom_z:z3740:*:*:*:*:*:*:*
intel atom_z z3740d cpe:2.3:h:intel:atom_z:z3740d:*:*:*:*:*:*:*
intel atom_z z3745 cpe:2.3:h:intel:atom_z:z3745:*:*:*:*:*:*:*
intel atom_z z3745d cpe:2.3:h:intel:atom_z:z3745d:*:*:*:*:*:*:*
intel atom_z z3770 cpe:2.3:h:intel:atom_z:z3770:*:*:*:*:*:*:*
intel atom_z z3770d cpe:2.3:h:intel:atom_z:z3770d:*:*:*:*:*:*:*
intel atom_z z3775 cpe:2.3:h:intel:atom_z:z3775:*:*:*:*:*:*:*
intel atom_z z3775d cpe:2.3:h:intel:atom_z:z3775d:*:*:*:*:*:*:*
intel atom_z z3785 cpe:2.3:h:intel:atom_z:z3785:*:*:*:*:*:*:*
intel atom_z z3795 cpe:2.3:h:intel:atom_z:z3795:*:*:*:*:*:*:*

References for CVE-2017-5753

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html Mailing List Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 Third Party Advisory
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html Exploit Third Party Advisory VDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt Third Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt Third Party Advisory
http://www.kb.cert.org/vuls/id/584653 Third Party Advisory US Government Resource
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html Patch Third Party Advisory
http://www.securityfocus.com/bid/102371 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040071 Third Party Advisory VDB Entry
http://xenbits.xen.org/xsa/advisory-254.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0292 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/speculativeexecution Third Party Advisory
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ Third Party Advisory
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ Third Party Advisory
https://cdrdv2.intel.com/v1/dl/getContent/685359 Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-002 Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-003 Third Party Advisory
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability Third Party Advisory
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html Third Party Advisory
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html Mailing List Third Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 Patch Third Party Advisory Vendor Advisory
https://seclists.org/bugtraq/2019/Jun/36 Issue Tracking Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201810-06 Third Party Advisory
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html Third Party Advisory
https://security.netapp.com/advisory/ntap-20180104-0001/ Third Party Advisory
https://spectreattack.com/ Technical Description Third Party Advisory
https://support.citrix.com/article/CTX231399 Third Party Advisory
https://support.f5.com/csp/article/K91229003 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us Third Party Advisory
https://support.lenovo.com/us/en/solutions/LEN-18282 Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel Third Party Advisory
https://usn.ubuntu.com/3540-1/ Third Party Advisory
https://usn.ubuntu.com/3540-2/ Third Party Advisory
https://usn.ubuntu.com/3541-1/ Third Party Advisory
https://usn.ubuntu.com/3541-2/ Third Party Advisory
https://usn.ubuntu.com/3542-1/ Third Party Advisory
https://usn.ubuntu.com/3542-2/ Third Party Advisory
https://usn.ubuntu.com/3549-1/ Third Party Advisory
https://usn.ubuntu.com/3580-1/ Third Party Advisory
https://usn.ubuntu.com/3597-1/ Third Party Advisory
https://usn.ubuntu.com/3597-2/ Third Party Advisory
https://usn.ubuntu.com/usn/usn-3516-1/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4187 Third Party Advisory
https://www.debian.org/security/2018/dsa-4188 Third Party Advisory
https://www.exploit-db.com/exploits/43427/ Exploit Third Party Advisory VDB Entry
https://www.kb.cert.org/vuls/id/180049 Third Party Advisory US Government Resource
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Patch Third Party Advisory
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ Third Party Advisory
https://www.synology.com/support/security/Synology_SA_18_01 Third Party Advisory
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html Third Party Advisory
cvelogic Threat Intelligence