Intel stuffs 77 vulnerabilities with microcode updates and discovers new zombie loading malware

0
8




from Claus Ludewig
In the new patch Intel closes a total of 77 vulnerabilities, which were spotted on various products of the house. These include not only processors but also network cards and drivers for the iGPU. In addition, Intel has discovered a new version of the malware called Zombieload and gives tips for hedging.

The processor manufacturer Intel has closed in new security updates a total of 77 security holes, the company said. Especially the gaps named CVE-2019-0169 and CVE-2019-11171 are considered critical by Intel. Thus, with the first-mentioned gap, it is possible for an attacker to spy on information when he is in the same or a neighboring network as the user. The updates are available for several different product categories. These include, for example, CPUs and network cards. Incidentally, the manufacturer has announced a new variant of the side channel attack Zombieload.

Zombieload in a new version

Already in May, researchers had discovered the side channel attack called Zombieload. After the attacks called Specter and Meltdown, Zombieload is another attack on processors. Here, the isolation of simultaneously running processes is overcome. The malware can read data from other processes. Intel had already provided a microcode update in May. Now a new version of the zombie loading malware has been discovered and made public by the manufacturer. On the Intel website, microcode updates are available for download for a number of products.


Incidentally, Intel advises not only to install the microcode updates for the Intel products, but also to use the current operating system together with cumulative updates at the same time. Also, the installation of the latest firmware of a device is advisable, Intel said. However, even then you are not immune from Zombieload. To be on the safe side, disable the processor feature called Transactional Synchronization Extensions. With this extension, speed advantages are generated by the parallel processing of program code. Also enabled hyperthreading is a gateway for the zombie loading malware.

06:07
Hyperthreading on or off? What's the technology in games with 12 or more cores?

Also worth reading: Zombieload, RIDL, Fallout, Yet Another Meltdown: New vulnerabilities in Intel CPUs

Facts about Patchday at Intel:

  • As Intel has announced, microcode updates are now available for a variety of in-house products. The new drivers close 77 vulnerabilities.
  • This includes a new variant of the side channel attack called Zombieload. With this malware it is possible to read data from processes of a computer.
  • In addition to installing the updates for Intel products, the manufacturer also advises installing the latest version of the operating system or current firmware from PC manufacturers.
  • To better protect against Zombieload, Intel recommends switching off the processor function called Transactional Synchronization Extensions, as this is the only way to prevent the parallel execution of program code. However, this may bring about a speed drop.

advertisement: CPU order now at Amazon
Sources: Heise, Intel

Also popular with PCGH readers: Zen 2 in full splendor: Ryzen 3000 and Rome under the microscope (1)TOP

Zen 2 in full splendor: Ryzen 3000 and Rome under the microscope

If you always wanted to know what CPUs look like under the hood, you should take a look at the latest pictures of the Berlin "Fritz's Fritz". (PLUS) CPU Benchmarks 2019 (2)

(PLUS) New CPU tests: From Core i5-2500K to Ryzen 9 3900X

PCGH Plus: An updated test methodology, ten dewy games, five (new) applications and powerful hardware. Analogous to the new GPU benchmarks, we also revised our CPU test course and show an example of eight eight-year processors. The article is from PC Games Hardware 10/2019.

AMD Ryzen 9 3950X: All specifications and known details in the video

Soon, the new 16-core CPU from AMD will be released. For this reason, we summarize in the video all the important specifications and details of the Ryzen 9 3950X and give initial forecasts of what the performance could be compared to the Intel CPUs.





(PLUS) Tuning Ryzen R7 2700 (X) and R5 2600 (X): Turbo, Overclocking, Voltage, RAM, Sub-Timings



(PLUS) Tuning Ryzen R7 2700 (X) and R5 2600 (X): Turbo, Overclocking, Voltage, RAM, Sub-Timings



PCGH Plus: The new Ryzen generation prevails over its predecessor models, especially thanks to higher clock frequencies. We show how the advantage of the R7 2700 (X) and R5 2600 (X) can be increased. The article is from PC Games Hardware 07/2018.
more …


go to Article




Source link
https://www.pcgameshardware.de/CPU-CPU-154106/News/Intel-stopft-77-Sicherheitsluecken-mit-Microcode-Updates-1336930/

Dmca

LEAVE A REPLY

Please enter your comment!
Please enter your name here