More

    New Spectre-based CPU vulnerability allows guests to steal sensitive data from the cloud




    • ETH Zurich researchers found a new Spectre-BTI attack called VMSCAPE that lets a VM steal host data
    • It affects cloud setups using KVM/QEMU on AMD and Intel CPUs, bypassing existing defenses
    • They propose flushing the branch predictor on VMEXIT as a low-cost fix

    If Ghostbusters taught us anything, it’s that spectres are notoriously difficult to get rid of.

    Security researchers from the Swiss public university, ETH Zurich, recently discovered a new Spectre-BTI (Branch Target Injection) attack that allows a malicious virtual machine (VM) to leak sensitive data from the host system, without modifying host software.

    https://cdn.mos.cms.futurecdn.net/MmSZkX83aFDh9nX7mrMNBK.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img