TEE.Fail attack breaks confidential computing on Intel, AMD, NVIDIA CPUs
ID: bb3695b4-2ac3-586e-b277-23709b415d02
STIX ID: report--bb3695b4-2ac3-586e-b277-23709b415d02
Feed Name: Bleeping Computer
Threat Score
Researchers from Georgia Tech and Purdue disclosed TEE.Fail, a DDR5 memory-bus interposition side-channel attack that can extract cryptographic keys and forge attestations from TEEs (Intel SGX/TDX and AMD SEV-SNP) by observing deterministic AES-XTS ciphertext on DRAM; the proof-of-concept uses a <$1,000 snooping rig, requires physical access and kernel-level privileges, and was responsibly disclosed to vendors who acknowledged the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
