Home / Component / CPU / Intel’s new vulnerability steals data by altering the CPU voltage and frequency

Intel’s new vulnerability steals data by altering the CPU voltage and frequency

A group of academics from different European universities have reported a new vulnerability for Intel processors, named Plundervolt. The report was made on June 7 2019, and Intel has already released firmware patches for this bug.

Intel SGX (Software Guard Extensions) uses enclaves, an isolated area, to protect sensitive computations. The protected computations cannot be read or edited from the outside of the enclave.

According to the researchers, by adjusting the frequency and the voltage of a processor “through privileged software interfaces”, it's possible to undermine the system's security, corrupting the integrity of Intel SGX on Intel CPUs.

By combining the Rowhammer and the CLKSCREW methodologies, two previously known attacks that tinker with the charge of memory cells and the CPU's energy management system, Plundervolt was discovered. By adjusting the CPU's frequencies and voltage, some bits within SGX are altered. This alteration causes errors that can be used at a later date to reconstruct the data that was within the enclave.

Plundervolt needs root/administrator access to be executed, making a remote attack rather difficult. Unlike other attacks, it's not possible to use this exploit through virtual machines.

The processors affected by this vulnerability include Intel's 6th, 7th, 8th, 9th, and 10th-Gen Core CPUs, as well as the Xeon E3, v5, v6, E-2100 and E-2200 series according to ZDNet.

Applying the firmware patches will lock the voltage and frequency to default values, turning software overclocking applications useless if the SGX is enabled. It's not known if these firmware patches will have any impact on the systems' performance.

If you want to know more about Plundervolt, click HERE.

KitGuru says: Will you download the firmware patches, knowing that you might lose your overclock profile?

Become a Patron!

Check Also

Nvidia reveals plans to manufacture AI supercomputers and Blackwell GPUs in the US

Nvidia is looking to bring some of its manufacturing over to the US. Today, the …

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!