CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷

°ä²¼¹¦·ò 2019-12-12


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


1.²¼¾°ÃèÊö


½üÈÕ £¬£¬ £¬£¬£¬£¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÆëÈ«ÐÔµÄPlundervolt·ì϶£¨CVE-2019-11157£© £¬£¬ £¬£¬£¬£¬¸Ã·ì϶¿ÉÓÃÓÚ¸´Ô­¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰ°²È«µÄÈí¼þÖÐÒýÈëÃýÎ󡣡£¡£¡£ ¡£¡£Intel̨ʽ»ú¡¢·þÎñÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£¡£¡£¡£ ¡£¡£


2.·ì϶Áбí


CVE    ID£º    CVE-2019-11157

·ì϶µÈ¼¶£º    ¸ßΣ

CVSSÆÀ·Ö£º    7.9

CVSSVector:  CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

·ì϶·ÖÀࣺ    ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶

Ó°ÏìÁìÓò£º    Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦ÖÃÆ÷

                    Intel?ÖÁÇ¿?´¦ÖÃÆ÷E3 v5ºÍv6

                    Intel?ÖÁÇ¿?´¦ÖÃÆ÷E-2100ºÍE-2200¼Ò×å


3.·ì϶ÏêÇé


ijЩIntel£¨R£©´¦ÖÃÆ÷ÖеĵçѹÉèÖôæÔÚ²»ÕýÈ·µÄǰÌá²é³­ÎÊÌâ £¬£¬ £¬£¬£¬£¬¿ÉÄÜ»áÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£¡£¡£¡£ ¡£¡£

Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þ°²È«Ö°ÄÜ £¬£¬ £¬£¬£¬£¬SGXΪÀûÓ÷¨Ê½Ìṩһ¸ö¿ÉÐŵÄÖ´Ðл·¾³¡£¡£¡£¡£ ¡£¡£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄÒ»Óײ¿ÃÅÉÏÔËÐÐ £¬£¬ £¬£¬£¬£¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æ·Ö¸ô£©ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù½øÐиôÀë¡£¡£¡£¡£ ¡£¡£


Plundervolt¹¥»÷½áºÏÁËÁ½ÖÖ¹¥»÷¼¼Êõ £¬£¬ £¬£¬£¬£¬Ô̺¬Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£¡£¡£¡£ ¡£¡£PlundervoltÀûÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥ÔªÄÚ²¿µÄµçѹºÍƵÂÊ £¬£¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÓÃÒª¸ü¸Ä¡£¡£¡£¡£ ¡£¡£ÕâЩ¸ü¸Ä²»»á·ÛËéSGXµÄ±£ÃÜÐÔ £¬£¬ £¬£¬£¬£¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦ÖõÄÊý¾ÝÖÐÒýÈëÃýÎó £¬£¬ £¬£¬£¬£¬¼´Plundervolt²»»á·ÛËéSGX £¬£¬ £¬£¬£¬£¬¶øÖ»»á·ÛËéÆäÊä³ö¡£¡£¡£¡£ ¡£¡£ÀýÈç £¬£¬ £¬£¬£¬£¬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢ÃýÎó £¬£¬ £¬£¬£¬£¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â £¬£¬ £¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»¸´Ô­ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£ ¡£¡£


Plundervolt²»Äܱ»Ô¶³ÌÀûÓà £¬£¬ £¬£¬£¬£¬²¢ÇÒ±ØÒªroot»òadminÌØÈ¨´ÓÖ¸±êÖ÷»úÉÏÔËÐз¨Ê½¡£¡£¡£¡£ ¡£¡£´Ë±í £¬£¬ £¬£¬£¬£¬PlundervoltÎÞ·¨ÔÚÐé¹¹»¯»·¾³£¨ÀýÈçÐé¹¹»úºÍÔÆÍÆËã·þÎñ£©ÖÐÔËÐС£¡£¡£¡£ ¡£¡£


4.½¨¸´½¨Òé


IntelÔÚ°²È«´«µÝINTEL-SA-00289Öа䲼ÁËÓйØÎ¢´úÂëºÍBIOS¸üС£¡£¡£¡£ ¡£¡£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ïî £¬£¬ £¬£¬£¬£¬Äܹ»ÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕý·çÏÕµÄÇé¿öϽûÓÃϵͳÉϵĵçѹºÍƵÂʽÚÔì½çÃæ¡£¡£¡£¡£ ¡£¡£


5.²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html

https://plundervolt.com/

https://github.com/KitMurdock/plundervolt

https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/