Recentl, Intel issued a notice assigning an official identifier to the Spoiler vulnerability. The Spoiler vulnerability became known a month ago after reports from experts at Worcester Polytechnic Institute in Massachusetts and the University of Lübeck (Germany). If it comforts anyone, in vulnerability databases, Spoiler will be referred to as vulnerability CVE-2019-0162. For pessimists, Intel does not plan to release patches to mitigate the risk of attacks using CVE-2019-0162. The company believes that conventional methods of mitigating side-channel attacks can protect against Spoiler.

It is worth noting that the Spoiler vulnerability (CVE-2019-0162) does not by itself allow for the extraction of sensitive user data without their knowledge. It merely serves as a tool to enhance and make more probable a breach utilizing the long-known Rowhammer vulnerability. This attack is a type of side-channel attack, targeting DDR3 memory with ECC (Error Correction Code). It is also possible that DDR4 memory with ECC is susceptible to the Rowhammer vulnerability, but experimental proof has yet to confirm this. In any case, if we haven't missed anything, there have been no reports on this matter.
Using Spoiler, one can link virtual addresses to physical addresses in memory. In other words, it enables the identification of specific memory cells to target with Rowhammer to substitute data in physical memory. Simultaneously altering just three bits of data in memory bypasses ECC and grants the attacker freedom of action. Access to the address mapping requires access to the computer at a non-privileged user level. This factor reduces the threat posed by Spoiler, but does not eliminate it. Experts estimate that the threat level of Spoiler is 3.8 out of 10.

Vulnerabilitățile Spoiler afectează toate procesoarele Intel Core, începând cu prima generație. Modificarea microcodului pentru a le remedia ar duce la o scădere semnificativă a performanței procesoarelor. „După o analiză amănunțită, Intel a stabilit că protecția existentă a nucleului de tip KPTI [izolarea memoriei nucleului] reduce riscul scurgerilor de date prin niveluri privilegiate. Intel recomandă utilizatorilor să respecte practicile obișnuite pentru a reduce exploatarea unor astfel de vulnerabilități [cu atacuri prin canale laterale].
Sursa: 3dnews.ru
