Thunderclap vulnerabilities allow the creation of very dangerous malicious peripherals that can steal data from the operating system's memory.
Windows , Mac, Linux, and FreeBSD systems are affected by a new vulnerability, revealed this week at NDSS 2019.
The vulnerability – called Thunderclap – affects how Thunderbolt-based peripherals can connect and interact with these operating systems, allowing a malicious device to steal data directly from the operating system's memory, including highly sensitive information.
The research team studying this vulnerability says that “all Apple laptops and desktops released since 2011 are vulnerable, with the exception of the 12-inch MacBook.”.
“Many laptops and desktops designed to run Windows or Linux and released since 2016 are also affected” (as long as they support Thunderbolt interfacing).
What is Thunderbolt?
Thunderbolt is the name of a hardware interface designed by Apple and Intel to allow the connection of external peripherals (keyboards, chargers, network cards, etc.) to a computer.
These interfaces became extremely popular because they combine different technologies, such as the ability to transmit DC power (for charging purposes), serial data (via PCI Express), and video output (via DisplayPort).
The technology was initially available for Apple devices, but then became available to all hardware vendors, and today it is everywhere, thanks to the latest version Thunderbolt 3.
But according to the research team, all Thunderbolt versions are affected by the Thunderclap vulnerability. This means that Thunderbolt 1 and 2 (the versions that use the Mini DisplayPort [MDP] connector) and Thunderbolt 3 (the version that works via a USB-C port) are affected.
What is Thunderclap?
Thunderclap is a collection of bugs that affect the way the Thunderbolt hardware interface is implemented in operating systems.
At the core of this vulnerability, researchers say there is an issue in operating system design, where the operating system automatically "trusts" each newly connected peripheral device, granting it access to all of its memory - a situation called Direct Memory Access (DMA).
Thunderclap vulnerabilities allow attackers to create malicious peripheral devices, which when connected via a Thunderbolt port can perform their normal functions but also execute malicious code on the operating system without any restrictions.
This makes the Thunderclap attack extremely dangerous, as it can easily be hidden inside any peripheral device.
The Thunderclap vulnerabilities are even capable of bypassing an operating system security feature known as Input-Output Memory Management Units (IOMMUs) that hardware and operating system manufacturers created in the early 2000s to counter malicious peripherals that abuse their access to the entire operating system memory (known as a DMA attack).
What about this situation?
Researchers from the University of Cambridge, Rice University, and SRI International discovered the Thunderclap bugs in 2016 and have been working with various hardware and operating system versions for three years to fix them.
However, despite the warning, operating system manufacturers have not reacted much, resulting in most of the Thunderclap attacks, described in a research paper published today, still working. Here is the current status of the patches, according to the researchers:
Windows – “Microsoft has enabled IOMMU support for Thunderbolt devices in Windows 10 version 1803, which was released in 2018. Previous hardware, upgraded to 1803, requires a firmware update from the vendor. However, the more complex vulnerabilities remain.”.
MacOS – “In macOS version 10.12.4 and later, Apple addressed the vulnerability. However, there are still unresolved issues.”.
Linux – “Recently, Intel made some fixes in Linux version 5.0 (which is due for release soon) that enable IOMMU for Thunderbolt.”.
FreeBSD- “The FreeBSD Project has shown that malicious peripherals are not a threat to it. However, FreeBSD does not currently support Thunderbolt hotplugging.”.
However, most Thunderclap bugs still exist.
In the meantime, users are advised to disable Thunderbolt ports via BIOS/UEFI firmware settings and avoid connecting to peripherals from untrusted sources.
Technical details about the Thunderclap vulnerabilities are available in a research paper titled “Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy Peripherals”, available for download in PDF format from here and here.
