CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷
°ä²¼¹¦·ò 2019-12-12

1.²¼¾°ÃèÊö
½üÈÕ£¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÆëÈ«ÐÔµÄPlundervolt·ì϶£¨CVE-2019-11157£©£¬¸Ã·ì϶¿ÉÓÃÓÚ¸´Ô¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰ°²È«µÄÈí¼þÖÐÒýÈëÃýÎó¡£Intel̨ʽ»ú¡¢·þÎñÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£
2.·ì϶Áбí
CVE ID£º CVE-2019-11157
·ì϶µÈ¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.9
CVSSVector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
·ì϶·ÖÀࣺ ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶
Ó°ÏìÁìÓò£º Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦ÖÃÆ÷
Intel?ÖÁÇ¿?´¦ÖÃÆ÷E3 v5ºÍv6
Intel?ÖÁÇ¿?´¦ÖÃÆ÷E-2100ºÍE-2200¼Ò×å
3.·ì϶ÏêÇé
ijЩIntel£¨R£©´¦ÖÃÆ÷ÖеĵçѹÉèÖôæÔÚ²»ÕýÈ·µÄǰÌá²é³ÎÊÌ⣬¿ÉÄÜ»áÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£
Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þ°²È«Ö°ÄÜ£¬SGXΪÀûÓ÷¨Ê½Ìṩһ¸ö¿ÉÐŵÄÖ´Ðл·¾³¡£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄÒ»Óײ¿ÃÅÉÏÔËÐУ¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æ·Ö¸ô£©ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù½øÐиôÀë¡£
Plundervolt¹¥»÷½áºÏÁËÁ½ÖÖ¹¥»÷¼¼Êõ£¬Ô̺¬Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£PlundervoltÀûÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥ÔªÄÚ²¿µÄµçѹºÍƵÂÊ£¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÓÃÒª¸ü¸Ä¡£ÕâЩ¸ü¸Ä²»»á·ÛËéSGXµÄ±£ÃÜÐÔ£¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦ÖõÄÊý¾ÝÖÐÒýÈëÃýÎ󣬼´Plundervolt²»»á·ÛËéSGX£¬¶øÖ»»á·ÛËéÆäÊä³ö¡£ÀýÈ磬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢ÃýÎ󣬴ӶøÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»¸´ÔÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£
Plundervolt²»Äܱ»Ô¶³ÌÀûÓ㬲¢ÇÒ±ØÒªroot»òadminÌØÈ¨´ÓÖ¸±êÖ÷»úÉÏÔËÐз¨Ê½¡£´Ë±í£¬PlundervoltÎÞ·¨ÔÚÐé¹¹»¯»·¾³£¨ÀýÈçÐé¹¹»úºÍÔÆÍÆËã·þÎñ£©ÖÐÔËÐС£
4.½¨¸´½¨Òé
IntelÔÚ°²È«´«µÝINTEL-SA-00289Öа䲼ÁËÓйØÎ¢´úÂëºÍBIOS¸üС£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡ÏÄܹ»ÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕý·çÏÕµÄÇé¿öϽûÓÃϵͳÉϵĵçѹºÍƵÂʽÚÔì½çÃæ¡£
5.²Î¿¼Á´½Ó
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html
https://plundervolt.com/
https://github.com/KitMurdock/plundervolt
https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/


¾©¹«Íø°²±¸11010802024551ºÅ