Downfall attacks - Major exploit in Intel CPUs discovered by Google researcher
Downfall attacks - Major exploit in Intel CPUs discovered by Google researcher by volpe.eth17 🥝 • 3y • 0 views • 0 clicks | |
AI summary of the linked articleDaniel Moghimi describes Downfall, a vulnerability in Intel processors that lets software on one user's machine steal data from other users sharing that computer, and in cloud environments from other customers. The flaw, tracked as CVE-2022-40982, stems from the Gather instruction leaking the content of the internal vector register file during speculative execution. Moghimi introduced Gather Data Sampling (GDS) and Gather Value Injection (GVI) techniques to exploit it, and says it took two weeks to develop an end-to-end attack stealing OpenSSL encryption keys. The article says Intel is releasing a microcode update as mitigation, and that some workloads may see up to 50% overhead according to Intel. | |
Recommended by 1 curator | |
Characters remaining: 10,000 comment guidelines | |
