CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷
Ðû²¼Ê±¼ä 2019-12-12

1.Åä¾°ÐÎò
¿ËÈÕ£¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÍêÕûÐÔµÄPlundervoltÎó²î£¨CVE-2019-11157£©£¬¸ÃÎó²î¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰÇå¾²µÄÈí¼þÖÐÒýÈë¹ýʧ¡£Intel̨ʽ»ú¡¢·þÎñÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£
2.Îó²îÁбí
CVE ID£º CVE-2019-11157
Îó²îÆ·¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.9
CVSSVector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Îó²î·ÖÀࣺ ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶
Ó°Ïì¹æÄ££º Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦Öóͷ£Æ÷
Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E3 v5ºÍv6
Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E-2100ºÍE-2200¼Ò×å
3.Îó²îÏêÇé
ijЩIntel£¨R£©´¦Öóͷ£Æ÷ÖеĵçѹÉèÖñ£´æ²»×¼È·µÄÌõ¼þ¼ìÅÌÎÊÌ⣬¿ÉÄÜ»áÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£
Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þÇå¾²¹¦Ð§£¬SGXΪӦÓóÌÐòÌṩһ¸ö¿ÉÐŵÄÖ´ÐÐÇéÐΡ£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄһС²¿·ÖÉÏÔËÐУ¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æÍÑÀ룩ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù¾ÙÐиôÀë¡£
Plundervolt¹¥»÷ÍŽáÁËÁ½ÖÖ¹¥»÷ÊÖÒÕ£¬°üÀ¨Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£PlundervoltʹÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥Î»ÄÚ²¿µÄµçѹºÍƵÂÊ£¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÐëÒª¸ü¸Ä¡£ÕâЩ¸ü¸Ä²»»áÆÆËðSGXµÄ±£ÃÜÐÔ£¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦Öóͷ£µÄÊý¾ÝÖÐÒýÈë¹ýʧ£¬¼´Plundervolt²»»áÆÆËðSGX£¬¶øÖ»»áÆÆËðÆäÊä³ö¡£ÀýÈ磬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢¹ýʧ£¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ»Ö¸´ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£
Plundervolt²»¿É±»Ô¶³ÌʹÓ㬲¢ÇÒÐèÒªroot»òadminÌØÈ¨´ÓÄ¿µÄÖ÷»úÉÏÔËÐгÌÐò¡£±ðµÄ£¬PlundervoltÎÞ·¨ÔÚÐéÄ⻯ÇéÐΣ¨ÀýÈçÐéÄâ»úºÍÔÆÅÌËã·þÎñ£©ÖÐÔËÐС£
4.ÐÞ¸´½¨Òé
IntelÔÚÇ徲ת´ïINTEL-SA-00289ÖÐÐû²¼ÁËÏà¹ØÎ¢´úÂëºÍBIOS¸üС£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ï¿ÉÒÔÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕýΣº¦µÄÇéÐÎϽûÓÃϵͳÉϵĵçѹºÍƵÂÊ¿ØÖƽçÃæ¡£
5.²Î¿¼Á´½Ó
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html
https://plundervolt.com/
https://github.com/KitMurdock/plundervolt
https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/


¾©¹«Íø°²±¸11010802024551ºÅ