Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

California and Pennsylvania student papers team up to heal from wildfires

AI startup Cohere gets Ottogrid, the platform for conducting market research

How to start a business in the age of AI (and now is the best time)

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Researchers reveal flaws in new Intel CPUs that allow memory leaks and Specter V2 attacks
Identity

Researchers reveal flaws in new Intel CPUs that allow memory leaks and Specter V2 attacks

userBy userMay 16, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 16, 2025Ravi LakshmananHardware security/vulnerabilities

Researchers at EthZürich have discovered another security flaw that affects all modern Intel CPUs and leaks sensitive data from memory, indicating that a vulnerability known as Specter continues to haunt computer systems over seven years later.

A vulnerability known as Branch Privilege Injection (BPI) can be “exploited to exploit predicted calculations on the CPU (Central Processing Unit) in order to gain unauthorized access to information from other processor users,” says Eth Zurich.

Kaveh Razavi, head of Computer Security Group (COMSEC) and one of the research authors, said this drawback could affect all Intel processors, allowing bad actors to read working memory of another user on the same CPU as the contents of the processor’s cache.

Cybersecurity

The attack takes advantage of what is called the Branch Predictive Race Condition (BPRC) that comes up when a processor switches between predictive calculations for two users with different privileges, opening the door to a scenario where it can bypass the security barrier from the privileged process and utilize it to access sensitive information.

Intel has issued a microcode patch to address a vulnerability assigned the CVE identifier CVE-2024-45332 (CVSS V4 score: 5.7).

“They say that affecting the transient execution of indirect branch predictors of some Intel processors allows confidential information exposure caused by shared micro-work history predictors to potentially enable information disclosure via local access,” Intel said in an advisory released on May 13th.

This disclosure comes when researchers at Vrije Universiteit Amsterdam’s Systems and Network Security Group (VUSEC) detailed the Self-Training Spector V2 category in a codenamed training solo attack.

“Attackers can leak across control flows (e.g., kernel) and privilege boundaries within the same domain, allowing them to replicate classic Specter V2 scenarios without relying on a powerful sandboxed environment like EBPF,” says Vusec.

Cybersecurity

Hardware exploits tracked as CVE-2024-28956 and CVE-2025-24495 can leak kernel memory up to 17 kb/s for Intel CPUs. This study can completely destroy traditional user users, Guest-V2 attacks.

CVE-2024-28956 (CVSS V4 Score: 5.7) – Indirect Target Selection (ITS) affects Intel Core 9-11th and Intel Xeon 2nd-3rd. CVE-2025-24495 (CVSS V4 score: 6.8) – Lion Cove BPU problem affecting Intel CPUs with Lion Cove Core

Intel has sent out microcode updates for these defects, but AMD said it has corrected existing guidance on Specter and Meltdown, explicitly highlighting the risks associated with using Classic Berkeley Packet Filter (CBPF).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleNuggets and Thunder set up an NBA showdown to win the winner in Game 7 | Football News
Next Article Conference Industry Association and Manchester Central will join All Party Parliament Group for the event
user
  • Website

Related Posts

New HTTPBOT BOTNET launches over 200 precision DDOS attacks against gaming and high-tech sectors

May 16, 2025

Top 10 Best Practices for Effective Data Protection

May 16, 2025

Filless Remcos rats delivered via LNK files and MSHTA in PowerShell-based attacks

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

California and Pennsylvania student papers team up to heal from wildfires

AI startup Cohere gets Ottogrid, the platform for conducting market research

How to start a business in the age of AI (and now is the best time)

Florida’s only public HBCU chooses a lobbyist with ties to DeSantis as the next president

Trending Posts

Israel launches strikes in two Yemeni ports | Hotel News

May 16, 2025

Israel kills hundreds and destroys fatal week in Gaza | Israeli-Palestinian conflict news

May 16, 2025

NJ Transit workers will take a strike after wages increase. Worker Rights News

May 16, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

How to start a business in the age of AI (and now is the best time)

Openai launches Codex: a cloud agent for software engineers who write code, fix bugs, and handle tasks in parallel

Google One surges to 150 million subscribers after launching AI-powered plans

What is the fit in the product market? A quick guide for non-technical founders

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.