Intel ´¦Öóͷ£Æ÷Ó²¼þ¡°VoltJockey¡±£¨ÆïÊ¿£©Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-11157£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.9£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Intel Core µÚ6¡¢7¡¢8¡¢9ºÍµÚ10´ú´¦Öóͷ£Æ÷
Intel Xeon ´¦Öóͷ£Æ÷E3 v5ºÍv6
Intel Xeon ´¦Öóͷ£Æ÷E-2100 ºÍ E-2200
Îó²î¸ÅÊö
2019Äê12ÔÂ10ÈÕ£¬£¬£¬£¬Intel¹ÙÆÓֱʽȷÈϲ¢Ðû²¼ÁË¡°VoltJockey¡±£¨ÆïÊ¿£©Îó²îͨ¸æ¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÏÖ´úÖ÷Á÷´¦Öóͷ£Æ÷΢ϵͳ¼Ü¹¹Éè¼ÆÊ±½ÓÄɵĶ¯Ì¬µçÔ´ÖÎÀíÄ£¿£¿£¿£¿£¿£¿£¿£¿éDVFS£¨Dynamic Voltage and Frequency Scaling£©±£´æÇå¾²Òþ»¼Ôì³ÉµÄ£¬£¬£¬£¬±£´æÌáȨºÍÐÅϢй¶µÄΣº¦¡£¡£¡£
VoltJockeyÎó²î»ùÓÚµçѹ¹ÊÕÏ×¢Èë¶ÔCPU¾ÙÐй¥»÷£¬£¬£¬£¬Ê¹ÓÃÓ²¼þ¹ÊÕ϶ÔCPUµÄÓ²¼þ¸ôÀëÉèÊ©£¨ÈçTrustZone£©¾ÙÐй¥»÷¡£¡£¡£²î±ðÓڹŰå½ÓÄɱà³Ì½Ó¿ÚÎó²îµÄ¹¥»÷·½·¨£¬£¬£¬£¬¸ÃÒªÁìÍêÈ«½ÓÄÉCPUµÄÓ²¼þÎó²î£¬£¬£¬£¬·ÀÓùÆðÀ´Ïà¶ÔÄÑÌ⣬£¬£¬£¬ÇÒ¹ØÓÚÀàËÆTrustZoneµÄÆäËüCPUµÄÓ²¼þÇå¾²À©Õ¹Ò²ÓÐÀàËÆÐ§¹û¡£¡£¡£ÏÖÔÚVoltJockeyÎó²îÆÕ±é±£´æÓÚÖ÷Á÷´¦Öóͷ£Æ÷оƬÖУ¬£¬£¬£¬¿ÉÄÜÉæ¼°Ä¿½ñ´ó×ÚʹÓõÄÊÖ»úÖ§¸¶¡¢ÈËÁ³/Ö¸ÎÆÊ¶±ð¡¢Çå¾²ÔÆÅÌËãµÈ¸ß¼ÛÖµÃܶÈÓ¦ÓõÄÇå¾²£¬£¬£¬£¬Ó°ÏìÃæ¹ã¡£¡£¡£
ÁíÍâ¸ÃÇå¾²Îó²î½öµ±ÔÚIntel SGX£¨Software Guard Extensions£©¿ªÆôʱ²Å±£´æ¡£¡£¡£IntelÒѾÏòÏµÍ³ÖÆÔìÉÌÐû²¼Á˹̼þ¸üУ¬£¬£¬£¬ÒÔ»º½âÕâһDZÔÚµÄÎó²î¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
Intel½¨ÒéÊÜÓ°ÏìµÄÓû§ÓëÏµÍ³ÖÆÔìÉÌÁªÏµ£¬£¬£¬£¬ÒÔ»ñÈ¡¿É»º½â´ËÎÊÌâµÄ×îÐÂBIOS¡£¡£¡£
²Î¿¼Á´½Ó
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html


¾©¹«Íø°²±¸11010802024551ºÅ