Intel ´¦Öóͷ£Æ÷Ó²¼þ¡°VoltJockey¡±£¨ÆïÊ¿£©Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11157£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.9£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Intel Core µÚ6¡¢7¡¢8¡¢9ºÍµÚ10´ú´¦Öóͷ£Æ÷

Intel Xeon ´¦Öóͷ£Æ÷E3 v5ºÍv6

Intel Xeon ´¦Öóͷ£Æ÷E-2100 ºÍ E-2200


Îó²î¸ÅÊö


2019Äê12ÔÂ10ÈÕ£¬£¬£¬Intel¹ÙÆÓֱʽȷÈϲ¢Ðû²¼ÁË¡°VoltJockey¡±£¨ÆïÊ¿£©Îó²îͨ¸æ¡£ ¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÏÖ´úÖ÷Á÷´¦Öóͷ£Æ÷΢ϵͳ¼Ü¹¹Éè¼ÆÊ±½ÓÄɵĶ¯Ì¬µçÔ´ÖÎÀíÄ£¿£¿£¿£¿£¿£¿éDVFS£¨Dynamic Voltage and Frequency Scaling£©±£´æÇå¾²Òþ»¼Ôì³ÉµÄ£¬£¬£¬±£´æÌáȨºÍÐÅϢй¶µÄΣº¦¡£ ¡£¡£¡£


VoltJockeyÎó²î»ùÓÚµçѹ¹ÊÕÏ×¢Èë¶ÔCPU¾ÙÐй¥»÷£¬£¬£¬Ê¹ÓÃÓ²¼þ¹ÊÕ϶ÔCPUµÄÓ²¼þ¸ôÀëÉèÊ©£¨ÈçTrustZone£©¾ÙÐй¥»÷¡£ ¡£¡£¡£²î±ðÓڹŰå½ÓÄɱà³Ì½Ó¿ÚÎó²îµÄ¹¥»÷·½·¨£¬£¬£¬¸ÃÒªÁìÍêÈ«½ÓÄÉCPUµÄÓ²¼þÎó²î£¬£¬£¬·ÀÓùÆðÀ´Ïà¶ÔÄÑÌ⣬£¬£¬ÇÒ¹ØÓÚÀàËÆTrustZoneµÄÆäËüCPUµÄÓ²¼þÇå¾²À©Õ¹Ò²ÓÐÀàËÆÐ§¹û¡£ ¡£¡£¡£ÏÖÔÚVoltJockeyÎó²îÆÕ±é±£´æÓÚÖ÷Á÷´¦Öóͷ£Æ÷оƬÖУ¬£¬£¬¿ÉÄÜÉæ¼°Ä¿½ñ´ó×ÚʹÓõÄÊÖ»úÖ§¸¶¡¢ÈËÁ³/Ö¸ÎÆÊ¶±ð¡¢Çå¾²ÔÆÅÌËãµÈ¸ß¼ÛÖµÃܶÈÓ¦ÓõÄÇå¾²£¬£¬£¬Ó°ÏìÃæ¹ã¡£ ¡£¡£¡£


ÁíÍâ¸ÃÇå¾²Îó²î½öµ±ÔÚIntel SGX£¨Software Guard Extensions£©¿ªÆôʱ²Å±£´æ¡£ ¡£¡£¡£IntelÒѾ­ÏòÏµÍ³ÖÆÔìÉÌÐû²¼Á˹̼þ¸üУ¬£¬£¬ÒÔ»º½âÕâһDZÔÚµÄÎó²î¡£ ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


Intel½¨ÒéÊÜÓ°ÏìµÄÓû§ÓëÏµÍ³ÖÆÔìÉÌÁªÏµ£¬£¬£¬ÒÔ»ñÈ¡¿É»º½â´ËÎÊÌâµÄ×îÐÂBIOS¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html