Exploiting System Management Mode with a very long interrupt
Researchers have identified a security vulnerability in the x86 System Management Mode (SMM) that can be exploited using an extremely long-running machine instruction. By forcing a core to remain busy, an attacker can desynchronize the SMM state across CPU cores to execute unauthorized code.
Why it matters
This represents a critical hardware-level security flaw that could potentially compromise the most privileged execution environment on modern computers.
Exploiting System Management Mode with a very very very very very very very long interrupt.
It turns out that you can break SMM — the secure, ultra privileged execution environment running invisibly in the background of every x86 CPU — with nothing more than an obscenely long-running machine instruction.
SMM requires that all cores are either in SMM or out of SMM at the same time. Its security model doesn't work without this - when one thread enters SMM, it makes all the others enter too.
To break this, all we need is someone too busy to notice they're supposed to join SMM.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in