New Security Vulnerabilities Found In Intel Processors

June 5, 2019

Written by wukovits

Remember the Spectre and Meltdown CPU vulnerabilities discovered early last year?  Well, hold onto your hat, because they’ve got company.

Recently, researchers discovered a new class of side-channel vulnerabilities in Intel processors that impact every modern chipset the company makes, including those used in Apple devices.

The new vulnerabilities exploit weaknesses in something called ‘speculative execution’ which is a core design feature of modern processors. This feature allows them to speculatively execute instructions based on conditions the system has ‘learned’ are likely to be true.  If those assumptions are proved to be valid, then the execution continues.  If not, it is discarded. The net effect of this design is to increase overall system performance speed, but it also opens up the door for additional risk.

The researchers had this to say about their latest discoveries:

“The new vulnerabilities can be used by motivated hackers to lead privileged information data from an area of the memory that hardware safeguards deem off-limits.  It can be weaponized in highly targeted attacks that would normally require system-wide privileges or deep subversion of the operating system.”

Collectively, these new vulnerabilities are being referred to as ‘MDS speculative execution’ flaws, and have been identified as follows:

  • CVE-2019-11091 – Microarchitectural Data Sampling Uncacheable Memory (MDSUM), part of the RIDL class of attacks.
  • CVE-2018-12127 – Microarchitectural Load Port Data Sampling (MLPDS), also part of the RIDL class of attacks.
  • CVE-2018-12130 – Microarchitectural Fill Buffer Data Sampling (MFBDS), also called ‘Zombieload’ or RIDL (Rogue In-Flight Data Load).
  • CVE-2018-12126 – Microarchitectural Store Buffer Data Sampling (MSBDS), also known as a Fallout

Of these, the ZombieLoad attacks seem to be the most worrisome of the lot.  They impact the largest number of chips, encompassing everything Intel has produced from 2011 onwards, but all of these are considered serious security flaws.  Worse, there are no fixes yet, and no word yet on when a fix might be forthcoming.

Used with permission from Article Aggregator

Bayou Tech

We provide solutions for your business. Find out how we can help.

Related Articles

New Graphene Technology May Increase Hard Drive Storage

HDDs are old, well understood technology. They haven't changed much in recent years. In fact, increasingly, people are writing them off, preferring SSDs for their greater speed and smaller size, even though HDDs are less expensive. The clever folks at the University...

Some Amazon Device Features May Have Security Risks

Have you heard of Amazon Sidewalk? If not, it's definitely something you should be aware of. Depending on your point of view, the new feature, which was enabled by default on a wide range of Amazon devices by default on June 8 of this year (2021) is either...

Email Unsubscribe Scam Can Easily Fool Any User

Scammers are increasingly relying on a tried and true bit of social engineering to fool unsuspecting users into unwittingly signing up to receive a flood of additional spam email. They accomplish this by blasting out an email asking recipients if they wish to...

Send us a message

Your message was sent.