Yet Another Meltdown – A Microarchitectural Fill Buffer Data Sampling Vulnerability (CVE-2018-12130)
Đăng ngày: 16 thg 5, 2019 · Tin tức · 1 phút đọc

More than one year ago, security researchers at Google Project Zero have disclosed a series of hardware vulnerabilities affecting Intel® x86 microprocessors. Leveraging a feature of modern processors called speculative execution, as well as timing responses, this family of flaws in hardware defeats the architectural safeguards of the processor and allows unprivileged user-mode applications to steal kernel-mode memory information processed on the affected computer.
Bitdefender Senior Researchers Dan Horea LUȚAȘ and Andrei Vlad LUȚAȘ, who spearhead the company’s threat research efforts as part of the Exploit Detection and Mitigation technologies for Bitdefender, and Hypervisor Introspection and Memory Protection program, respectively, have uncovered in August 2018 a new vulnerability that shares similarities with Meltdown.
This new vulnerability found by Bitdefender can be used by determined hackers to leak privileged data from an area of the memory that hardware safeguards deem off-limits. This flaw can be weaponized in highly targeted attacks that would normally require either system-wide privileges or deep subversion of the operating system to achieve similar results.
Of particular importance is the impact of this vulnerability on cloud service providers and multi-tenant environments, where virtualized instances sharing the same hardware can be used to read sensitive data belonging to other customers.
The proof of concept code shared privately with the vendor at the time of discovery has proven effective on several Intel® CPU microarchitectures. A technical demonstration of the vulnerability is described in a whitepaper available for download below
Read more about the vulnerability on the Intel Security Center.
We will update this post as more related work is currently documented.
Bài viết liên quan

Bảo vệ gia đình bạn khỏi thủ đoạn lừa đảo AI "Tiếng khóc trẻ em" vô cùng tinh vi
Đăng ngày: 21 thg 7, 2026
Đọc bài viết
Data Breach (Rò rỉ dữ liệu) là gì? Và tại sao Bitdefender lại là giải pháp bảo mật tối ưu nhất?
Đăng ngày: 19 thg 7, 2026
Đọc bài viết
Cơn Sốt Bóng Đá: Đừng Để Kẻ Gian Ghi Bàn Vào Hệ Thống Bảo Mật Kỹ Thuật Số Của Bạn
Đăng ngày: 15 thg 6, 2026
Đọc bài viết
Người dùng Android cần xem ngay! 3 cách cài đặt khóa điện thoại chống ứng dụng ẩn danh hút sạch tiền tài khoản (Cập nhật mới nhất)
Đăng ngày: 12 thg 6, 2026
Đọc bài viết