Intel processors hit with another serious security flaw impacting millions of PCs
Researchers say the security flaw, which works similarly to the Meltdown and Spectre attacks discovered last year, affects Intel CPUs going back to 2008.
What you need to know
- Researchers at several institutions have discovered another serious security flaw in Intel processors.
- The attack vector is similar to last year's Meltdown and Spectre flaws, and four variants have been proven to work so far.
- Potentially millions of PCs and servers are affected, allowing hackers to gain access to sensitive data.
- Microsoft is rolling out a fix today, while Intel says it has one ready to roll out on its end as well.
Early in 2018, two major vulnerabilities, dubbed Spectre and Meltdown, were discovered by researchers in Intel and AMD processors. While mitigations have since been released from Intel, AMD, Microsoft, and other major hardware and software companies, the method of attack, which takes advantage of a process called speculative execution, has led researchers to discover a set of four more attacks that impact Intel processors dating back to 2008, Wired reports.
Intel has collectively dubbed the attacks "Microarchitectural Data Sampling" (MDS). And while the set of four attacks all operate in a similar manner to Meltdown and Spectre, these new MDS attacks (ZombieLoad, Fallout, and RIDL) appear to be easier to execute. From Wired:
Each variant of the attack can be used as a gateway into viewing raw data that passes through a processor's cache before it is tossed discarded through the speculative execution process. If executed quickly in succession, a hacker could gather enough random data to piece together everything from passwords to the keys used to decrypt hard drives.
"In essence, [MDS] puts a glass to the wall that separates security domains, allowing attackers to listen to the babbling of CPU components," VUSec, one of the firms that discovered the flaws, said in a paper set to be presented next week and seen by Wired.
A video of ZombieLoad, one of the four attacks, in action, showing how it can be used to log what websites you visit.
Those who discovered the attacks include researchers from the Austrian university TU Graz, Vrije Universiteit Amsterdam, the University of Michigan, the University of Adelaide, KU Leuven in Belgium, Worcester Polytechnic Institute, Saarland University in Germany and Cyberus, BitDefender, Qihoo360 and Oracle, Wired says.
In speaking with Wired, Intel says its own researchers discovered the flaw last year and it now has fixes available at the hardware and software level. The company also says some processors shipped in last month have fixed the vulnerability.
Get the Windows Central Newsletter
All the latest news, reviews, and guides for Windows and Xbox diehards.
However, Intel and the researchers disagree on the severity of the flaw. While Intel rates the attacks as "low to medium" in severity, researchers from the institutions that discovered the attacks told Wired that they could "reliably dig through that raw output to find the valuable information they sought."
For its part, Microsoft shipped a fix for Windows PCs today. In a statement to Wired, a Microsoft spokesperson said, "We're aware of this industry-wide issue and have been working closely with affected chip manufacturers to develop and test mitigations to protect our customers."
While fixes may be starting to become available, it will take time for them to be applied to PCs and servers affected by the four variants. That raises concerns that the attacks could be used on potentially millions of machines around the world to access sensitive data before they are patched, if at all.
Affordable accessories that'll pair perfectly with your PC
Every one of these awesome PC accessories will enhance your everyday experience — and none cost more than $30.
KLIM Aim RGB gaming mouse ($30 at Amazon)
Whether you're a gamer or not, this is an absurdly good mouse for the price. It's ambidextrous, has a responsive sensor, a braided cable, tank-like build quality, and, yes, it has RGB lighting, though you can turn it off if that's not your thing.
AmazonBasics USB speakers ($16 at Amazon)
These neat little speakers may only pack 2.4W of total power, but don't let that fool you. For something so small you get a well-rounded sound and a stylish design. And they only cost $16.
Razer mouse bungee ($20 at Amazon)
Use a wired mouse? You need a mouse bungee to keep your cable tidy and free of snags. You get no drag on the cable, and this one has subtle styling, a rust-resistant spring and a weighted base, all for $20.
Dan Thorp-Lancaster is the former Editor-in-Chief of Windows Central. He began working with Windows Central, Android Central, and iMore as a news writer in 2014 and is obsessed with tech of all sorts. You can follow Dan on Twitter @DthorpL and Instagram @heyitsdtl.