Meltdown and Spectre CPU Vulnerabilities Cause Panic


05 Jan 2018

Meltdown and Spectre CPU Vulnerabilities Cause Pan...

In what is being described as ‘one of the worst CPU bugs ever’, serious security flaws have been found in processors designed by Intel, AMD and ARM that could enable hackers to steal sensitive data.

Academics working alongside Google’s Project Zero have reported that the two flaws, named Meltdown and Spectre, affect a range of modern devices including smartphones, tablets and PCs from all vendors and running almost any operating system.

The Meltdown flaw primarily affects Intel processors manufactured since 1995 and could allow malicious actors to access privileged memory on a device. A fix is available, but it requires a change to the way the operating system handles memory and some pessimistic headlines have estimated this could detrimentally affect the speed of some machines by up to 30%.

Although it is harder for attackers to exploit, the underlying Spectre vulnerability is more serious as it affects most modern processors made by Intel, AMD and ARM. Again, this potentially allows hackers to access sensitive information, but most worrying is that the issue is a fundamental processor design flaw. Some experts, including the US-CERT, have suggested the only real solution for these issues is for chips to be totally replaced, but this could take years to resolve.

It is important to realise that these issues are not solely a problem with Intel, as was initially being reported in some articles. All major vendors such as Microsoft, Apple and Google have released patches or mitigating advice during this rapidly evolving incident and, although there is a compromise in performance when issuing a fix, we encourage users to install patches at their earliest opportunity.

 

author

By Olly Jones

Senior Cyber Threat Analyst

Share this article

RISK PORTAL

Your free Global Geopolitical Dashboard

PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.

The Risk Portal gives users up-to-date information and analysis on global affairs.

The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.

Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.

Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.

Visit the Risk Portal

Subscribe to our Cyber Bytes Newsletter

Keep yourself in the loop with PGI by signing up to our Weekly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.

Related News

CISMP, CISSP and CISM - what's in an acronym?

20 Mar 2017

There is a wide range of different security courses available, and a mind-boggling array of certific...

Read news article

International Womens Day - Pioneering Women in Tec...

08 Mar 2017

Pioneering Women in Technology – Katherine JohnsonThe Oscar season has been and gone. The...

Read news article

Law Firms and why they need cyber security

06 Mar 2017

Suffering a data breach can be devastating for any company but for law firms the impacts can be part...

Read news article
Back to the News Hub

Follow us

+44 (0)207 887 2699
©2017 PGI - Protection Group International Ltd. All rights reserved.
PGI - Protection Group International Ltd is registered in England & Wales, reg. no. 07967865
Registered address: Cascades 1, 1190 Park Avenue, Aztec W, Almondsbury, Bristol BS32 4FP