Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Intel CPU exploit threatens PCs worldwide

  • Email a Friend
  • Print Page
By Chuck Miller
Mar 23, 2009 11:10 AM
Tags: Intel | CPU | exploit | processor | PC | SMM
Researchers at Invisible Things Lab have released information on a security exploit that could compromise PCs that run on Intel processors.

Researchers at Invisible Things Lab have released information on a security exploit that could compromise PCs that run on Intel processors.

In a paper describing the exploit, Invisible's Joanna Rutkowska and Rafal Wojtczuk claimed that the attack, involving cache poisoning in a CPU operation mode called System Management Mode (SMM), was the third their team had found affecting Intel-based systems within the last 10 months.

“It seems that current state of firmware security, even in cases of such reputable vendors as Intel, is quite unsatisfying,” they wrote in the paper.

An attack based on the Intel exploit could poison a chip's cache memory, which would enable forced access to SMM, the most privileged CPU mode on x86 architectures. Even operating systems cannot access SSM, which handles certain errors, power management and other features. According to Rutkowska and Wojtczuk, exploitation of the CPU cache could mean dumping the contents of RAM used for SSM, or enabling arbitrary code execution in that memory.

The potential consequence of attacks on SMM might include SMM rootkits, hypervisor compromises, or OS kernel protection bypassing, they said.

Intel has been working on a solution to prevent caching attacks on SMM memory, and a spokesperson has said that many new systems are protected against the exploit. But, writing in their paper, Rutkowska and Wojtczuk said: “Some of Intel's recent motherboards, like the popular DQ35, are still vulnerable to the attack. Additionally, the workarounds that Intel has mentioned to us are not yet officially documented.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers