According to a publication by German tech website heise.de, Intel processors are affected by eight new Specter-class vulnerabilities.
The website states that the bugs have already been assigned CVE IDs and that at least one of them will be disclosed by Project Zero της Google στις 7 Μαΐου, μια μέρα πριν το Patch Tuesday της Microsoft.
The site reports that it has concrete evidence that Intel processors are vulnerable to new vulnerabilities and that AMD processors may also be vulnerable. According to the publication, it is now reported that further investigations are being conducted on the latter.
Meanwhile, Intel issued a statement entitled "Troubleshooting Additional Security Issues".
"Protecting our customers' data and ensuring the safety of our products are critical priorities for us. We work closely with customers, partners, other chip makers and researchers to understand and mitigate any issues identified, ”says Leslie Culbertson, Intel vice president.
We strongly believe in the value of coordinated disclosure and we will share additional details about possible issues as we complete our investigations. As a best practice, we continue to encourage everyone to keep their systems up to date.
According with Heise, four of the vulnerabilities have been labeled "high risk" and, as is the case with its defects Spectre previously identified, affect cloud providers due to the ability to attack a host system from a virtual machine, allowing an attacker to obtain passwords from the host's memory.
Να υπενθυμίσουμε ότι το ελάττωμα Specter Variant 2, επηρέαζε τις εταιρείες Cloud λόγω του ότι μπορούσε να χρησιμοποιηθεί για την παράκαμψη του Hypervisor. Fixing it required microcode updates from Intel and AMD.
Heise reports that although the first Spectre vulnerabilities were difficult to exploit, 8 novices can be more easily used.
It should also be mentioned that Intel has not yet confirmed that it is trying to repair the specific vulnerabilities.
Intel's press release without algae for silk ribbons