Sunday March 21, 2010 6:07 AM AEST

Intel CPU security vulnerability

  • Email a Friend
  • Print Page
Intel CPU security vulnerability
By Justin Robinson
Mar 23, 2009 | 1 Comment
Tags: Intel | CPU | security | vulnerability

Flaw in the design makes virtualisation a security risk - but to who?

When you're dealing with architectures on a microscopic scale, eventually you run into problems, and that's what Intel has faced quite often.

From Translation Lookside Buffer bugs to lawsuits and unpleasantness, Intel has had their share of problems already, but this one affects the security of all of their CPUs out today.

Discovered by Johanna Rutkowska at Invisible Things Lab, there is a loophole in the CPU design that allows a program to access the second ring of the operating system (where the drivers are loaded).

While this doesn't sound too bad, it gives the program essentially free reign over the hardware, and is buried deep enough that simple virus scans can't detect it.

Arstechnica provides a very nice summary of how this is achieved:

An attacker who wishes to modify the code within the SMM must first locate the SMRAM region within system memory and designate it as a write-back cache. Once the address range is properly specified, our hypothetical hacker "creates write accesses to the SMRAM's physical address range." Because the space as been previously set as WB cacheable, the accesses are cached rather than rejected. Next, the attacker triggers a System Management Interrupt (SMI), which orders the CPU to enter System Management Mode and execute the code therein. The CPU drops into SMM happily enough, but when it fetches code from SMRAM, it fetches the corrupted cached data first. The result, says Rutkowska, is that "the above scenario allows for arbitrary SMM memory overwrite (and later code execution...)."

Basically tricking the system into thinking that the corrupted data will allow other code to run without too much worry.

Intel is working on fixing it however, and while this security flaw might seem quite terrible, it also is rather tricky to exploit en masse, so your rig will probably survive for just long enough for Intel to patch it through a BIOS update.

 

 
 
Want to check out the first Australian review of Final Fantasy XIII? We got in this month's Atomic!

Plus HD projectors, Napoleon: Total War, Intel's new six-core processor, PC upgrading guide, and a whole lot more.

ON SALE NOW!
1 Comment
Thoughts on this article? Add a comment below.
hello0011
Mar 27, 2009 9:01 PM
sounds like a challenge....i might think...
Login or register to submit a comment.
 
 
Atomic Magazine

Issue: 111 | April, 2010

Atomic is a magazine aimed squarely at computer enthusiasts, gamers, and serious PC upgraders.

Every month we bring you the latest reviews of new technology and PC components, in depth features on everything from overclocking to console hacking, and gaming previews and interviews.
 
Latest Comments
"Send your good taste to celebration by delivering our mouthwatering cakes to Dehradun and exotic ..."
by rony24 | Mar 20, 2010 4:56 PM
 
"So. Much. Awesome."
by The Manta | Mar 20, 2010 4:23 PM
 
"@sirtrancealot, BF started on the PC and BC1 only on Consoles was a kick to the PC gamers ..."
by NRUFrost | Mar 20, 2010 8:14 AM
 
"RAGE!!!"
by Hawkeye | Mar 20, 2010 1:24 AM
 
"alex - bugger all. 78mg of caffeine. About the same as a cup of instant coffee. Taurine, Gurana ..."
by tantryl | Mar 20, 2010 12:51 AM
 
1) Nokia E7147 plans 33%
2) Apple iPhone 3GS 32GB36 plans 33%
3) Apple iPhone 8GB43 plans 22%
4) HTC Magic5 plans 33%
5) Nokia N9740 plans 33%
1) iiNet32 plans 100%
2) Optus41 plans 14%
3) Vodafone7 plans 5%
4) Telstra BigPond30 plans 1%
5) Dodo34 plans 6%

Mobiles | Broadband | Credit Cards

Haymarket - Atomic MPC
Latest User Reviews
Logitech MX518 Gaming-Grade Optical Mouse
90%
Good shape, design and Ergonomics
 
Coolermaster HAF 922
100%
A case to make a statment and give your pc the Heavy Hardcore Grunt it needs.
 
Coolermaster Excalibur
50%
Atomic is under attack
 
XFX 9300 Motherboard
40%
HUGE letdown
 
CM Storm Sentinel gaming mouse
90%
Sexy and instant geek respect.