HomeSecurityIntel: CPU vulnerability affects desktop and server systems

Intel: CPU vulnerability affects desktop and server systems

Intel has fixed a serious vulnerability in modern desktop, server, mobile, and embedded CPUs , including the latest Alder Lake, Raptor Lake, and Sapphire Rapids microarchitectures .

Intel CPU vulnerability

Cybercriminals can exploit this vulnerability (CVE-2023-23583) to gain elevated privileges on vulnerable systems, gain access to sensitive information, or trigger a denial of service state.

See also: LockBit ransomware: Exploits Citrix Bleed vulnerability in attacks

“Under certain microarchitectural conditions, Intel has identified cases where executing an instruction (REP MOVSB) coded with a “redundant REX prefix” may lead to unpredictable system resulting in a system crash/halt or, in certain limited scenarios, may allow escalation of privilege (EoP) from CPL3 to CPL0,” Intel said.

“Redundant REX prefixes are not expected to exist in code or be generated by compilers. Malicious exploitation of this issue requires code execution. Intel has identified an escalation of privilege vulnerability in limited scenarios, in a controlled Intel lab environment,” the company said.

Specific systems with affected processors, including those with Alder Lake, Raptor Lake, and Sapphire Rapids, have already received updated microcodes prior to November, with no performance impacts or other issues observed.

See also: WP Fastest Cache plugin: SQL injection vulnerability puts thousands of WordPress sites at risk

The company has also released microcode updates to address the issue for other CPUs. Users are advised to update their BIOS, system operating system, and drivers to get the latest microcode from their original equipment (OEM), operating system vendor (OSV), and hypervisor vendors.

The full list of Intel processors affected by the CVE-2023-23583 vulnerability is available here.

Intel recommends updating affected processors as soon as possible to protect systems .

Intel: CPU vulnerability affects desktop and server systems

 “Very strange” vulnerability

Google researcher Tavis Ormandyrevealed that this flaw was also discovered by multiple research groups within Google, including Google Information Security Engineering and the silifuzz team. The researchers named the vulnerability Reptar.

Earlier this year, Google security researchers discovered the Downfall vulnerability affecting modern Intel CPUs and the Zenbleed vulnerability , which allows attackers to steal sensitive data like passwords and encryption keys from systems with AMD Zen2 processors

See also: Microsoft: Patch Tuesday November 2023 released

CPU vulnerabilities

CPU vulnerabilities affect digital security in many ways. Successful exploitation of them could allow malware to gain access to sensitive information stored in the device's memory. This could include personal data, passwords, or even encrypted messages.

Additionally, a CPU vulnerability can impact system performance, as attacks that exploit this vulnerability can consume valuable computer resources. This can lead to system slowdowns and loss of performance.

Finally, there may be implications for the security of encrypted communications. Attackers exploiting this weakness could decrypt encrypted messages and gain access to sensitive information.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS