Intel's Cascade Lake CPUs impacted by new Zombieload v2 attack
#1
Exclamation 
Quote:Researchers have disclosed a new variant of the attack method dubbed ZombieLoad, which appears to also impact Intel CPUs that are not affected by the first variant of ZombieLoad.
 
In May, a team of researchers, including experts who brought to light the existence of speculative execution side-channel vulnerabilities such as Meltdown and Spectre, disclosed several new flaws affecting Intel processors. These new attack methods rely on Microarchitectural Data Sampling (MDS) vulnerabilities and they have been dubbed ZombieLoad, RIDL and Fallout.
 
The MDS vulnerabilities can be exploited by a malicious application to obtain potentially sensitive information from other apps, the operating system, and virtual machines. The attacks work against both PCs and cloud environments, and they can be leveraged to obtain information such as passwords, website content, disk encryption keys and browser history.
 
When they first disclosed the MDS vulnerabilities, researchers said they impacted most Intel CPUs made in the past decade, but they did not affect some of the newer processors. However, the same researchers revealed on Tuesday that they have also uncovered a second variant of the ZombieLoad attack, which works against CPUs that include hardware mitigations against MDS attacks.
 
According to the experts, ZombieLoad Variant 2 also works against Intel Xeon Gold server processors with Cascade Lake microarchitecture and Core i9 processors with Coffee Lake microarchitecture.
ZombieLoad Variant 2, tracked as CVE-2019-11135, is related to Intel’s Transactional Synchronization Extensions (TSX), which is designed to improve performance for multi-threaded software. ZombieLoad Variant 2, which Intel has described as a Transactional Asynchronous Abort (TAA) vulnerability, affects all CPUs that support TSX and have the TAA_NO bit set to 0.

Read more: https://www.securityweek.com/newer-intel...oad-attack
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Nvidia GeForce Game Ready Driver 610.52 ...
Nvidia GeForce Gam...harlan4096 — 07:41
Mozilla Firefox Browser 151.0.4
Mozilla Firefox Br...harlan4096 — 07:39
Adobe Acrobat Reader DC 26.001.21662
Adobe Acrobat Read...harlan4096 — 07:38
PowerToys v0.100.0
Release v0.100.0 ...harlan4096 — 07:37
Brave 1.91.171 (Chromium 149.0.7827.103)
Release v1.91.171 ...harlan4096 — 07:36

[-]
Birthdays
Today's Birthdays
avatar (42)zacforat
avatar (47)NemrokReks
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>