CVE-2020-0551, known as Load Value Injection (LVI), is a class of transient execution attacks affecting a wide range of Intel processors. LVI enables an attacker to inject arbitrary data into a victim's transient execution stream by exploiting microarchitectural buffers (such as L1D cache, store buffer, line-fill buffer, and load ports). This attack is particularly severe for Intel SGX enclaves, where it can be used to hijack control flow and extract sensitive data, including cryptographic keys. LVI is distinct from previous Meltdown-type attacks in that it enables data injection rather than just data leakage, and it is not mitigated by existing Meltdown or Spectre defenses. Exploitation requires the attacker to induce page faults or microcode assists in the victim and to locate suitable code gadgets that use the injected data. The attack surface is extensive, as nearly any memory load could potentially be an LVI gadget.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) for the LVI-LFB (Load Value Injection - Line Fill Buffer) Control Flow Hijacking attack, specifically targeting CVE-2020-0551. The exploit demonstrates how an attacker can hijack the control flow of another process on vulnerable Intel CPUs by spraying the line fill buffers with the address of a malicious function ('PoisonFunction'). The main code is in 'src/lvi_cfh_poc/lvi_cfh_poc.c' (C) and 'src/lvi_cfh_poc/asmhelper.asm' (assembly), with build files for Visual Studio. The PoC creates two threads: one continuously sprays the LFBs, and the other attempts to speculatively execute code via indirect branches, measuring cache access times to detect successful exploitation. The exploit is local, requires specific hardware and OS configuration, and does not provide a weaponized payload but rather demonstrates the vulnerability's feasibility. No network or external endpoints are present; the only fingerprintable target is the specific memory address used to detect speculative execution. The repository is well-structured for research and demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.