Mark Ermolov (@_markel___) on X

1 min read Original article ↗

Post

Post

  • user avatar

    Wow, we (+

    @h0t_max

    and

    @_Dmit

    ) have found two undocumented x86 instructions in Intel CPUs which completely control microarchitectural state (yes, they can modify microcode)

  • user avatar

    They're decoded in all modes (even in User Mode) but the ucode in MSROM throws #UD if not in Red Unlocked state. All details a little later...

  • user avatar

    For our followers: The likely implication is that an attacker who can access the machine in early-boot mode, can circumvent Intel's signed firmware protections. The ultimate impact remains to be seen.

  • user avatar

    Does this relate to Minix running in the shadows on Intel's hardware in any way? What I recall was that in Intel's silicon was an embedded Minix "security management" function that was operating entirely outside of the local control IIRC. I think it was remote manage "feature".

  • user avatar

    Having the platform red-unlocked is already game over, perhaps except for SGX.

Don't miss what's happening

People on X are the first to know.