A researcher will demonstrate the exploitable bugs of Intel's CPUs by attacking both locally and remotely, regardless of the patches applied or operating system.
Researcher and technical writer Kris Kaspersky will actually showcase
how such an attack can be made in a presentation at the upcoming Hack In The Box (HITB)
Security Conference in Kuala Lumpur, Malaysia, 27th -30th October.
According to the Intel Specification Updates, Intel Core 2 has 128 confirmed bugs. Intel Itanium (designed for critical systems) is carrying over 230 bugs. They have all been confirmed by Intel and described in errata section of their specification updates. Some bugs "just" crash the system (under quite rare conditions) while the others give the attackers full control over the machine. "In other words, Intel CPUs have exploitable bugs which are vulnerable to both local and remote attacks which works against any OS regardless of the patches applied or the applications which are running," Kaspersky says.
Although CPU bugs are not something new in the security industry, nobody has come out with any proof-of-concept exploits and as it stands, there are no known malware that take advantage of these bugs, although some malware writers have actually used CPU bugs for targeted attacks.
"It is just a matter of time before we start seeing these sort of attacks used in more devastating ways over the Internet. Intel has provided workarounds to major BIOS vendors for some of these bugs, but who knows which vendor actually uses them " End-users are in the dark as to how to check if they are secure or not. Intel doesn't provide any test program for this and the worst thing is - some bugs are still not fixed. In other words, Intel has no workaround for it."