6.7
CVSSv3

CVE-2019-11157

Published: 16/12/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 410
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intel xeon e3-1585 firmware -

intel xeon e3-1585l firmware -

intel xeon e3-1578l firmware -

intel xeon e3-1575m firmware -

intel xeon e3-1565l firmware -

intel xeon e3-1558l firmware -

intel xeon e3-1545m firmware -

intel xeon e3-1535m firmware -

intel xeon e3-1515m firmware -

intel xeon e3-1505m firmware -

intel xeon e3-1505l firmware -

intel xeon e3-1280 firmware -

intel xeon e3-1275 firmware -

intel xeon e3-1270 firmware -

intel xeon e3-1268l firmware -

intel xeon e3-1260l firmware -

intel xeon e3-1245 firmware -

intel xeon e3-1240l firmware -

intel xeon e3-1240 firmware -

intel xeon e3-1235l firmware -

intel xeon e3-1230 firmware -

intel xeon e3-1225 firmware -

intel xeon e3-1220 firmware -

intel xeon e3-1501l firmware -

intel xeon e3-1501m firmware -

intel xeon e3-1285 firmware -

intel core i3-6300 firmware -

intel core i3-6300t firmware -

intel core i3-6320 firmware -

intel core i3-6100e firmware -

intel core i3-6100h firmware -

intel core i3-6100u firmware -

intel core i3-6102e firmware -

intel core i3-6157u firmware -

intel core i3-6167u firmware -

intel core i3-6100 firmware -

intel core i3-6100t firmware -

intel core i3-6100te firmware -

intel core i3-6006u firmware -

intel core i3-6098p firmware -

intel core i5-6600 firmware -

intel core i5-6685r firmware -

intel core i5-6600k firmware -

intel core i5-6600t firmware -

intel core i5-6585r firmware -

intel core i5-6500 firmware -

intel core i5-6500t firmware -

intel core i5-6500te firmware -

intel core i5-6402p firmware -

intel core i5-6400 firmware -

intel core i5-6400t firmware -

intel core i5-6440eq firmware -

intel core i5-6440hq firmware -

intel core i5-6442eq firmware -

intel core i5-6360u firmware -

intel core i5-6350hq firmware -

intel core i5-6300hq firmware -

intel core i5-6300u firmware -

intel core i5-6200u firmware -

intel core i5-6260u firmware -

intel core i5-6267u firmware -

intel core i5-6287u firmware -

intel core i7-6970hq firmware -

intel core i7-6920hq firmware -

intel core i7-6870hq firmware -

intel core i7-6822eq firmware -

intel core i7-6820hq firmware -

intel core i7-6820hk firmware -

intel core i7-6820eq firmware -

intel core i7-6785r firmware -

intel core i7-6700k firmware -

intel core i7-6700t firmware -

intel core i7-6700te firmware -

intel core i7-6700 firmware -

intel core i7-6770hq firmware -

intel core i7-6700hq firmware -

intel core i7-6660u firmware -

intel core i7-6650u firmware -

intel core i7-6600u firmware -

intel core i7-6567u firmware -

intel core i7-6560u firmware -

intel core i7-6500u firmware -

intel core i5-8600t firmware -

intel core i5-8600k firmware -

intel core i5-8600 firmware -

intel core i5-8500t firmware -

intel core i5-8500b firmware -

intel core i5-8500 firmware -

intel core i5-8400t firmware -

intel core i5-8400h firmware -

intel core i5-8400b firmware -

intel core i5-8400 firmware -

intel core i5-8365ue firmware -

intel core i5-8365u firmware -

intel core i5-8350u firmware -

intel core i5-8310y firmware -

intel core i5-8305g firmware -

intel core i5-8300h firmware -

intel core i5-8279u firmware -

intel core i5-8269u firmware -

intel core i5-8265u firmware -

intel core i5-8259u firmware -

intel core i5-8257u firmware -

intel core i5-8250u firmware -

intel core i5-8210y firmware -

intel core i5-8200y firmware -

intel core i7-8665ue firmware -

intel core i7-8665u firmware -

intel core i7-8557u firmware -

intel core i7-8850h firmware -

intel core i7-8809g firmware -

intel core i7-8750h firmware -

intel core i7-8709g firmware -

intel core i7-8706g firmware -

intel core i7-8705g firmware -

intel core i7-8700t firmware -

intel core i7-8700k firmware -

intel core i7-8700b firmware -

intel core i7-8700 firmware -

intel core i7-8569u firmware -

intel core i7-8650u firmware -

intel core i7-8565u firmware -

intel core i7-8559u firmware -

intel core i7-8550u firmware -

intel core i7-8500y firmware -

intel core i7-8086k firmware -

intel core i3-8350k firmware -

intel core i3-8300 firmware -

intel core i3-8300t firmware -

intel core i3-8145ue firmware -

intel core i3-8145u firmware -

intel core i3-8130u firmware -

intel core i3-8109u firmware -

intel core i3-8100h firmware -

intel core i3-8100b firmware -

intel core i3-8100 firmware -

intel core i3-8100t firmware -

intel core i3-7350k firmware -

intel core i3-7320 firmware -

intel core i3-7300 firmware -

intel core i3-7300t firmware -

intel core i3-7130u firmware -

intel core i3-7102e firmware -

intel core i3-7101e firmware -

intel core i3-7101te firmware -

intel core i3-7100t firmware -

intel core i3-7100e firmware -

intel core i3-7100 firmware -

intel core i3-7167u firmware -

intel core i3-7100u firmware -

intel core i3-7100h firmware -

intel core i3-7020u firmware -

intel core i5-7600k firmware -

intel core i5-7600t firmware -

intel core i5-7600 firmware -

intel core i5-7500 firmware -

intel core i5-7500t firmware -

intel core i5-7442eq firmware -

intel core i5-7440hq firmware -

intel core i5-7440eq firmware -

intel core i5-7400t firmware -

intel core i5-7400 firmware -

intel core i5-7360u firmware -

intel core i5-7300u firmware -

intel core i5-7300hq firmware -

intel core i5-7287u firmware -

intel core i5-7267u firmware -

intel core i5-7260u firmware -

intel core i5-7200u firmware -

intel core i5-7y54 firmware -

intel core i5-7y57 firmware -

intel core i7-7920hq firmware -

intel core i7-7820hq firmware -

intel core i7-7820hk firmware -

intel core i7-7820eq firmware -

intel core i7-7700hq firmware -

intel core i7-7700 firmware -

intel core i7-7700k firmware -

intel core i7-7700t firmware -

intel core i7-7660u firmware -

intel core i7-7600u firmware -

intel core i7-7567u firmware -

intel core i7-7560u firmware -

intel core i7-7500u firmware -

intel core i7-7y75 firmware -

intel core i5-1035g7 firmware -

intel core i5-1035g4 firmware -

intel core i5-1035g1 firmware -

intel core i5-10310y firmware -

intel core i5-1030g7 firmware -

intel core i5-1030g4 firmware -

intel core i5-10210u firmware -

intel core i5-10210y firmware -

intel core i3-10110u firmware -

intel core i3-10110y firmware -

intel core i3-1000g4 firmware -

intel core i3-1000g1 firmware -

intel core i3-1005g1 firmware -

intel core i7-10710u firmware -

intel core i7-1065g7 firmware -

intel core i7-1060g7 firmware -

intel core i7-10510u firmware -

intel core i7-10510y firmware -

intel core i3-9350kf firmware -

intel core i3-9350k firmware -

intel core i3-9320 firmware -

intel core i3-9300t firmware -

intel core i3-9300 firmware -

intel core i3-9100te firmware -

intel core i3-9100t firmware -

intel core i3-9100hl firmware -

intel core i3-9100f firmware -

intel core i3-9100e firmware -

intel core i3-9100 firmware -

intel core i7-9850hl firmware -

intel core i7-9850he firmware -

intel core i7-9850h firmware -

intel core i7-9750hf firmware -

intel core i7-9750h firmware -

intel core i7-9700te firmware -

intel core i7-9700t firmware -

intel core i7-9700kf firmware -

intel core i7-9700k firmware -

intel core i7-9700f firmware -

intel core i7-9700e firmware -

intel core i7-9700 firmware -

intel core i5-9600t firmware -

intel core i5-9600k firmware -

intel core i5-9600kf firmware -

intel core i5-9600 firmware -

intel core i5-9500te firmware -

intel core i5-9500t firmware -

intel core i5-9500f firmware -

intel core i5-9500e firmware -

intel core i5-9500 firmware -

intel core i5-9400f firmware -

intel core i5-9400t firmware -

intel core i5-9400h firmware -

intel core i5-9400 firmware -

intel core i5-9300hf firmware -

intel core i5-9300h firmware -

intel xeon e-2186g firmware -

intel xeon e-2176g firmware -

intel xeon e-2146g firmware -

intel xeon e-2126g firmware -

intel xeon e-2104g firmware -

intel xeon e-2124g firmware -

intel xeon e-2144g firmware -

intel xeon e-2174g firmware -

intel xeon e-2134 firmware -

intel xeon e-2136 firmware -

intel xeon e-2124 firmware -

intel xeon e-2288g firmware -

intel xeon e-2278g firmware -

intel xeon e-2286g firmware -

intel xeon e-2276g firmware -

intel xeon e-2246g firmware -

intel xeon e-2236 firmware -

intel xeon e-2226g firmware -

intel xeon e-2274g firmware -

intel xeon e-2244g firmware -

intel xeon e-2234 firmware -

intel xeon e-2224g firmware -

intel xeon e-2224 firmware -

Vendor Advisories

Multiple security vulnerabilities have been identified by Intel Intel is releasing updates for BIOS, Voltage Modulation, Intel Processor Graphics, Intel SGX, Intel SGX and Intel TXT, Intel SGX and Intel Processor Graphics, Intel Trusted Execution Technology (TXT), Intel System Management Mode (SMM), Intel CPU Local Privilege Escalation, TSX Asynch ...
Multiple security vulnerabilities have been identified by Intel Intel is releasing updates for BIOS, Voltage Modulation, Intel Processor Graphics, Intel SGX, Intel SGX and Intel TXT, Intel SGX and Intel Processor Graphics, Intel Trusted Execution Technology (TXT), Intel System Management Mode (SMM), Intel CPU Local Privilege Escalation, TSX Asynch ...

Github Repositories

A guide to unlock voltage control on Dell laptops

Supported Models XPS 7590 Vostro 5471 (githubcom/Lyceris-chan) Most likely any model that has a K series skew CPU If you are able to make it work on a model not already listed please create a issue with your devices model Dell unlock Undervolting A guide to unlock voltage control on Dell laptops above BIOS version 161, Undervoltiong was locked away to preve

Tool Suite for V0LTpwn (CVE-2019-11157). Code will be published soon.

V0LTpwn V0LTpwn (CVE-2019-11157) is a software-controlled fault attack on x86 processors It is the first attack corrupting the integrity of SGX enclaves Description All recent Intel processors exhibit a software interface for controlling core voltages without rebooting the system This feature is not required for normal operation but is used by expert users for performance op

Recent Articles

Intel's SGX cloud-server security defeated by $30 chip, electrical shenanigans
The Register • Thomas Claburn in San Francisco • 14 Nov 2020

VoltPillager breaks enclave confidentiality, calls anti-rogue data-center operator promise into question One more reason for Apple to dump Intel processors: Another SGX, kernel data-leak flaw unearthed by experts

Boffins at the University of Birmingham in the UK have developed yet another way to compromise the confidentiality of Intel's Software Guard Extensions (SGX) secure enclaves, supposed "safe rooms" for sensitive computation. Over the past few years, the security of SGX, a set of security-oriented instructions used to set up so-called secure enclaves, has been assailed repeatedly by infosec types. These enclaves are intended to house software and data that not even the computer's administrators, o...

Intel's SGX cloud-server security defeated by $30 chip, electrical shenanigans
The Register • Thomas Claburn in San Francisco • 14 Nov 2020

VoltPillager breaks enclave confidentiality, calls anti-rogue data-center operator promise into question One more reason for Apple to dump Intel processors: Another SGX, kernel data-leak flaw unearthed by experts

Boffins at the University of Birmingham in the UK have developed yet another way to compromise the confidentiality of Intel's Software Guard Extensions (SGX) secure enclaves, supposed "safe rooms" for sensitive computation. Over the past few years, the security of SGX, a set of security-oriented instructions used to set up so-called secure enclaves, has been assailed repeatedly by infosec types. These enclaves are intended to house software and data that not even the computer's administrators, o...

Intel might want to reconsider the G part of SGX – because it's been plunderstruck
The Register • Thomas Claburn in San Francisco • 10 Dec 2019

I was caught in the middle of a memory attack, and I knew there was no turning back True to its name, Intel CPU flaw ZombieLoad comes shuffling back with new variant

Intel on Tuesday plans to release 11 security advisories, including a microcode firmware update to patch a vulnerability in its Software Guard Extensions (SGX) on recent Core microprocessors that allows a privileged attacker to corrupt SGX enclave computations. The SGX flaw has been dubbed Plundervolt by the computer scientists who found it – Kit Murdock, David Oswald, and Flavio Garcia from the UK's University of Birmingham, Daniel Gruss from Austria's Graz University of Technology, and Jo Va...