US-CERT- TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance

Started by Netwörkheäd, May 01, 2018, 06:10:21 PM

Previous topic - Next topic

Netwörkheäd

TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance

[html]Original release date: January 04, 2018 | Last revised: May 01, 2018

         

Systems Affected


         

CPU hardware implementations

         
         

Overview


         

On January 3, 2018, the National Cybersecurity and Communications Integration Center (NCCIC) became aware of a set of security vulnerabilities—known as https://meltdownattack.com/">Meltdown and https://spectreattack.com/">Spectre—that affect modern computer processors. These vulnerabilities can be exploited to steal sensitive data present in a computer systems' memory.

         
         

Description


         

CPU hardware implementations are vulnerable to side-channel attacks, referred to as Meltdown and Spectre. Meltdown is a bug that "melts" the security boundaries normally enforced by the hardware, affecting desktops, laptops, and cloud computers.

Let's not argue. Let's network!