Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2019-014
Version:
1.0
Affected software:
All systems running Intel CPUs manufactured since 2011 are vulnerable.
Type:
Hardware-based side-channel attack which allows attackers to compromise data confidentiality, including cleartext credentials or cryptographic keys stored in memory, which could lead to complete system compromise.
CVE/CVSS:
→ CVEs: CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091
→ CVSS Score: 6.5
Complete compromise of system confidentiality, integrity, and/or availability.
The Microarchitectural Data Sampling (MDS) vulnerabilities are similar to the Meltdown and Spectre vulnerabilities discovered in 2018. This newly-disclosed class of vulnerabilities affecting all Intel CPUs manufactured since 2011 has been given the nickname Zombieload. The researchers who discovered these vulnerabilities cooperated with Intel and major operating system vendors to do coordinated disclosure. At this time, there are no known cases of exploitation in the wild. However, with the release of proof-of-concept demos by the security researchers and the upcoming presentation of their paper at the IEEE Symposium on Security and Privacy on 20 May, it is only a matter of time before we start to see this class of vulnerabilities being exploited on a wide scale.
We recommend the following actions: