An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution.
| Software | From | Fixed in |
|---|---|---|
| microsoft / windows_10 | 1809 | 1809.x |
| microsoft / windows_10 | 1903 | 1903.x |
| microsoft / windows_10 | 1909 | 1909.x |
| microsoft / windows_10 | 2004 | 2004.x |