New Spectre-based CPU vulnerability allows guests to steal sensitive data from the cloud




  • ETH Zurich researchers found a new Spectre-BTI attack called VMSCAPE that lets a VM steal host data
  • It affects cloud setups using KVM/QEMU on AMD and Intel CPUs, bypassing existing defenses
  • They propose flushing the branch predictor on VMEXIT as a low-cost fix

If Ghostbusters taught us anything, it’s that spectres are notoriously difficult to get rid of.

Security researchers from the Swiss public university, ETH Zurich, recently discovered a new Spectre-BTI (Branch Target Injection) attack that allows a malicious virtual machine (VM) to leak sensitive data from the host system, without modifying host software.

https://cdn.mos.cms.futurecdn.net/MmSZkX83aFDh9nX7mrMNBK.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img