Spectre New attacks, security fixes come up

After patching the first wave of Specter and Meltdown attacks, many relaxed. Error. The Specter and Meltdown CPU vulnerabilities showed a whole new way to attack systems, and all security experts knew they were time to find new attack methods.

Jann Horn, security researcher at , such as seems discovered a new method in a short time after fixing the first Specter vulnerabilities. Horn found a new way to attack microprocessors. Spectre

The security gap doesn't just affect Intel processors. Also affects AMD (x86) chipsets, POWER 8, POWER 9, z and some ARM processors. In short, it could allow unauthorized read access to memory on almost any 21st century processor.

The number of the vulnerability (CVE) for this security is the CVE-2018-3639.

Intel calls this Speculative Store (SSB), also known as Specter Variant 4. Contrary to the error discovered by Yuriy Bulygin, the former head of Intel's advanced threat group, the xBNUMX system management systems of Intel (SMM), SBB is a new method of attack.

_____________________________

Another new but less dangerous Specter style security vacuum is that CVE-2018-3640, also known as Rogue System Register Read (RSRE) or Specter Variant 3a. With this vulnerability, local users may be able to obtain unauthorized disclosure of system parameters by analyzing side channels.

External attacks, through a browser and a malware page, are less likely with both Intel security loopholes.

This means (according to Intel):

“Most browser developers have recently developed Managed Runtimes mitigation measures, which greatly increase the difficulty of exploiting side channels. These techniques increase the difficulty of operating an SSB-based side channel from a browser. "

To solve the problem, Intel has released beta updates for beta system microprocessors and device manufacturers, adding support for Speculative Store Bypass Disable (SSBD). The SSBD provides additional protection, preventing the occurrence of the Speculative Store bypass. Intel hopes that most major operating systems will add support for Speculative Store Bypass Disable (SSBD) starting with 21 May 2018.

________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).