Breaking News

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating Logitech announces G512 X Gaming Keyboard ASUS Announces TUF Gaming Platinum Power Supply Series TerraMaster announces D1 SSD Rugged Enclosure COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Intel Reveals New Chip Security Flaw

Intel Reveals New Chip Security Flaw

PC components May 15,2019 0

Intel has disclosed Microarchitectural Data Sampling, or MDS, a new set of processor security flaws.

Although both Intel and security researchers who discovered the flaws have never seen exploits in the wild, they’ve been able to create exploits of their own as a proof of concept.

The Intel chipsets released this year include a fix for the flaws, but the flaws impact every Intel microprocessor released since 2011, so previous versions will need to be patched. Those patches are already available, but some, depending on the chipset, could slow performance by as much as 19 percent.

The security researchers who worked with Intel have released their own information about the flaws, and each has created sample exploits to demonstrate the issues. The RIDL and Fallout speculative execution attacks - that's the name the researchers gave to their tests - allow attackers to leak confidential data across arbitrary security boundaries on a victim system, for instance compromising data held in the cloud or leaking your information to malicious websites. The attacks leak data by exploiting the newly disclosed Microarchitectural Data Sampling (or MDS) side-channel vulnerabilities in Intel CPUs. Unlike existing attacks, the attacks orchestrated by the researchers can leak arbitrary in-flight data from CPU-internal buffers (Line Fill Buffers, Load Ports, Store Buffers), including data never stored in CPU caches. The researchers show that existing defenses against speculative execution attacks are inadequate, and in some cases actually make things worse. Attackers can use the specific attacks to obtain sensitive data despite mitigations, due to vulnerabilities deep inside Intel CPUs.

Another group of researchers has created an exploit called ZombieLoad.

“The ZombieLoad attack allows stealing sensitive data and keys while the computer accesses them,” the ZombieLoad website notes. “While programs normally only see their own data, a malicious program can exploit the fill buffers to get hold of secrets currently processed by other running programs. These secrets can be user-level secrets, such as browser history, website content, user keys, and passwords, or system-level secrets, such as disk encryption keys. The attack does not only work on personal computers but can also be exploited in the cloud.”

Amazon, Apple, Google, Microsoft, and Mozilla have all claimed to have issued fixes for the flaws.

AMD has confirmed that its processors are unaffected by the RIDL and Fallout vulnerabilities.

"...we believe our products are not susceptible to 'Fallout' or 'RIDL' because of the hardware protection checks in our architecture. We have not been able to demonstrate these exploits on AMD products and are unaware of others having done so," reads the AMD statement.

Tags: SecurityIntelProcessors
Previous Post
SpaceX To Launch 60 Starlink Satellites For Space Internet Service
Next Post
Microsoft Patches Older Versions of Windows Against Wormable Windows Bug

Related Posts

  • Intel Launches Intel Core Series 3 Processors

  • ASRock Unveils Intel Arc Pro B70 Graphics Cards, Redefining Professional Workspaces

  • G.SKILL DDR5 Memory Kits Confirmed as Intel XMP 3.0 'Ready' for Intel Core Ultra 200S Plus Series Processors

  • Intel Launches New Core Ultra 200HX Plus Series Mobile Processors

  • Intel Announces New Intel Core Ultra 200S Plus Series Desktop Processors

  • Intel Launches Core Series 2 Processor with Real-Time Performance and Expands Edge AI Portfolio

  • Intel Launches new Intel Xeon 600 Processors for Workstation

  • Intel Core Ultra Series 3 Debut at CES 2026

Latest News

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating
Enterprise & IT

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating

Logitech announces G512 X Gaming Keyboard
Gaming

Logitech announces G512 X Gaming Keyboard

ASUS Announces TUF Gaming Platinum Power Supply Series
PC components

ASUS Announces TUF Gaming Platinum Power Supply Series

TerraMaster announces D1 SSD Rugged Enclosure
Enterprise & IT

TerraMaster announces D1 SSD Rugged Enclosure

COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support
PC components

COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed