The toolkit for decoding Intel microcode has been released

A group of security researchers from the uCode team has published the source code for decoding Intel microcode. The Red Unlock technique, developed by the same researchers in 2020, can be used to extract encrypted microcode. The proposed decoding capability allows for the exploration of the internal structure of the microcode and the methods of implementation of x86 machine instructions. Additionally, the researchers have recovered the update format for the microcode, the encryption algorithm, and the key used to protect the microcode (RC4).

To determine the encryption key used, a vulnerability in Intel TXE was exploited, which enabled the activation of an undocumented debug mode that the researchers dubbed 'Red Unlock'. In this debug mode, it was possible to directly load a dump from the CPU containing the active microcode and extract the algorithm and keys from it.

The toolkit allows only for the decryption of microcode but does not permit any modifications, as the integrity of the microcode is additionally verified through a digital signature based on the RSA algorithm. This method is applicable to Intel processors in the Gemini Lake family based on the Goldmont Plus microarchitecture and Intel Apollo Lake based on the Goldmont microarchitecture.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster