01-29-2020, 08:42 AM
https://www.tomshardware.com/news/intel-...ut-attacks
https://www.techpowerup.com/263355/cache...processors
Quote:Researchers at the University of Michigan, VUSec and University of Adelaide revealed a new attack they dubbed CacheOut yesterday. The speculative execution attack "is capable of leaking data from Intel CPUs across many security boundaries," according to the researchers, and it offers better targeting than previous attacks of its type.
CacheOut was purportedly inspired by previous speculative execution attacks like Spectre and Meltdown. Its reach extends further than those attacks, however, because it can bypass the hardware-based safeguards implemented by Intel in response to Meltdown's discovery. It can also be used to extract specific data.
The researchers said they "empirically demonstrate that CacheOut can violate nearly every hardware-based security domain, leaking data from the OS kernel, co-resident virtual machines, and even SGX enclaves" in their paper. Intel released microcode updates, and explained how to mitigate the attack on the OS level, in response.
So who's affected? The researchers said that anyone who owns an Intel processor released before the fourth quarter of 2018 is probably affected by CacheOut. (The company "inadvertently managed to partially mitigate this issue while addressing a previous issue," they said.) Intel published a list of affected processors on its website.
...
The researchers said additional information about this new attack can be found in the final version of their paper (PDF). While the new CacheOut branding might make this attack seem totally new, it seems like ZombieLoad actually copied its namesake in rising from the dead to continue to munch on the sweet, sweet brains of our PCs.
https://www.techpowerup.com/263355/cache...processors
Quote:Additionally, it is worth pointing out that AMD CPUs are not affected by this exploit.

