SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    "CacheOut" Attack Targets Intel Processors
Date    Wednesday January 29 2020, @10:25PM
Author    Fnord666
Topic   
from the cash-out dept.
https://soylentnews.org/article.pl?sid=20/01/29/237212

takyon writes:

New 'CacheOut' attack targets Intel processors, with a fix arriving soon

Researchers have discovered and published information on what they're calling CacheOut, a vulnerability in most Intel CPUs that allows an attacker to target more specific data, even stored within Intel's secured SGX enclave.

Intel assigned what's known as the CVE-2020-0549 vulnerability a threat level of "medium," acknowledging the danger of a targeted attack. The company noted that CacheOut has never been used outside of a laboratory environment.

Among the threats CacheOut poses is to cloud providers, and leaking data from hypervisors (virtual machine monitors) and the virtual machines running on them. Because the researchers disclosed the CacheOut vulnerability privately to Intel some time before making it public, those cloud providers have already deployed countermeasures against CacheOut.

Intel said that it plans to release mitigations to address the issue in the near future. These normally are sent to users in the form of BIOS or driver updates.

Virtually all Intel processors are potentially affected by CacheOut, save for processors released after the fourth quarter of 2019. AMD processors are not affected, according to details released on a dedicated CacheOut site. Processors made by IBM and ARM may be affected, but have not been confirmed. The paper, by lead author researcher Stephan van Schaik of the University of Michigan and colleagues, has also been made public.


Original Submission

Links

  1. "takyon" - https://soylentnews.org/~takyon/
  2. "New 'CacheOut' attack targets Intel processors, with a fix arriving soon" - https://www.pcworld.com/article/3516302/new-cacheout-attack-targets-intel-processors-with-a-fix-arriving-soon.html
  3. "CacheOut" - https://cacheoutattack.com/
  4. "CVE-2020-0549 vulnerability" - https://software.intel.com/security-software-guidance/software-guidance/l1d-eviction-sampling
  5. "acknowledging the danger" - https://blogs.intel.com/technology/2020/01/ipas-intel-sa-00329/
  6. "affected" - https://software.intel.com/security-software-guidance/insights/processors-affected-l1d-eviction-sampling
  7. "paper" - https://cacheoutattack.com/CacheOut.pdf
  8. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=38846

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, "CacheOut" Attack Targets Intel Processors on 2024-05-01 16:20:38