New Intel CPU flaws leak sensitive data from privileged memory
ID: 580d748a-5671-5375-865f-6f23bc2c72e0
STIX ID: report--580d748a-5671-5375-865f-6f23bc2c72e0
Feed Name: Bleeping Computer
A newly disclosed Intel CPU hardware vulnerability (CVE-2024-45332, “Branch Privilege Injection”) allows speculative branch predictor updates to cross user/kernel privilege boundaries, enabling an unprivileged attacker to leak kernel and privileged memory; ETH Zurich demonstrated a proof-of-concept on Ubuntu that read /etc/shadow with up to 5.6 KB/s and high accuracy. Intel has released microcode mitigations (with modest performance overhead) and recommends BIOS/OS updates; researchers will publish full technical details at USENIX Security 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
