• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new research reveals spectre vulnerability persists in latest amd and

New Research Reveals Spectre Vulnerability Persists in Latest AMD and Intel Processors

You are here: Home / General Cyber Security News / New Research Reveals Spectre Vulnerability Persists in Latest AMD and Intel Processors
October 29, 2024

More than six years after the Spectre security flaw impacting modern CPU processors came to light, new research has found that the latest AMD and Intel processors are still susceptible to speculative execution attacks.

The attack, disclosed by ETH Zürich researchers Johannes Wikner and Kaveh Razavi, aims to undermine the Indirect Branch Predictor Barrier (IBPB) on x86 chips, a crucial mitigation against speculative execution attacks.

Speculative execution refers to a performance optimization feature wherein modern CPUs execute certain instructions out-of-order by predicting the branch a program will take beforehand, thus speeding up the task if the speculatively used value was correct.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


If it results in a misprediction, the instructions, called transient, are declared invalid and squashed, before the processor can resume execution with the correct value.

Cybersecurity

While the execution results of transient instructions are not committed to the architectural program state, it’s still possible for them to load certain sensitive data into a processor cache through a forced misprediction, thereby exposing it to a malicious adversary that would otherwise be blocked from accessing it.

Intel describes IBPB as an “indirect branch control mechanism that establishes a barrier, preventing software that executed before the barrier from controlling the predicted targets of indirect branches executed after the barrier on the same logical processor.”

It’s used as a way to help counter Branch Target Injection (BTI), aka Spectre v2 (CVE-2017-5715), a cross-domain transient execution attack (TEA) that takes advantage of indirect branch predictors used by processors to cause a disclosure gadget to be speculatively executed.

A disclosure gadget refers to the ability of an attacker to access a victim’s secret that’s otherwise not architecturally visible, and exfiltrate it over a covert channel.

The latest findings from ETH Zürich show that a microcode bug in Intel microarchitectures such as Golden Cove and Raptor Cove could be used to circumvent IBPB. The attack has been described as the first, practical “end-to-end cross-process Spectre leak.”

The microcode flaw “retain[s] branch predictions such that they may still be used after IBPB should have invalidated them,” the researchers said. “Such post-barrier speculation allows an attacker to bypass security boundaries imposed by process contexts and virtual machines.”

AMD’s variant of IBPB, the study discovered, can be similarly bypassed due to how IBPB is applied by the Linux kernel, resulting in an attack – codenamed Post-Barrier Inception (aka PB-Inception) – that enables an unprivileged adversary to leak privileged memory on AMD Zen 1(+) and Zen 2 processors.

Intel has made available a microcode patch to address the problem (CVE-2023-38575, CVSS score: 5.5). AMD, for its part, is tracking the vulnerability as CVE-2022-23824, according to an advisory released in November 2022.

“Intel users should make sure their intel-microcode is up to date,” the researchers said. “AMD users should make sure to install kernel updates.”

The disclosure comes months after ETH Zürich researchers detailed new RowHammer attack techniques codenamed ZenHammer and SpyHammer, the latter of which uses RowHammer to infer DRAM temperature with high accuracy.

Cybersecurity

“RowHammer is very sensitive to temperature variations, even if the variations are very small (e.g., ±1 °C),” the study said. “RowHammer-induced bit error rate consistently increases (or decreases) as the temperature increases, and some DRAM cells that are vulnerable to RowHammer exhibit bit errors only at a particular temperature.”

By taking advantage of the correlation between RowHammer and temperature, an attacker could identify the utilization of a computer system and measure the ambient temperature. The attack could also compromise privacy by using temperature measurements to determine a person’s habits within their home and the times when they enter or leave a room.

“SpyHammer is a simple and effective attack that can spy on temperature of critical systems with no modifications or prior knowledge about the victim system,” the researchers noted.

“SpyHammer can be a potential threat to the security and privacy of systems until a definitive and completely-secure RowHammer defense mechanism is adopted, which is a large challenge given that RowHammer vulnerability continues to worsen with technology scaling.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «chinese hackers use cloudscout toolset to steal session cookies from Chinese Hackers Use CloudScout Toolset to Steal Session Cookies from Cloud Services
Next Post: U.S. Government Issues New TLP Guidance for Cross-Sector Threat Intelligence Sharing u.s. government issues new tlp guidance for cross sector threat intelligence»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.