Spectre

Vulnerability updated 8 days ago (2024-11-29T14:27:47.025Z)
Download STIX
Preview STIX
Spectre, also known as Spectre-BHB or branch history injection (BHI), is a significant software vulnerability that was first exposed in 2018. This flaw in the design or implementation of CPU hardware utilizing speculative execution made computer memory an easy target for hackers. Attackers could exploit this vulnerability to inject malicious code and steal sensitive data, including usernames and passwords, by leveraging side-channel attacks such as timing attacks. The vulnerability proved to be a striking demonstration of the power of these types of attacks, despite not being a cryptographic attack in the traditional sense. The Spectre vulnerability has resurfaced with new hardware, AmpereOne, indicating its persistent threat to information security. A variant of the original Spectre v1 vulnerability, dubbed "GhostRace," exploits a race condition on a transiently executed path originating from a mis-speculated branch, similar to the original Spectre v1. This targets a racy code snippet or gadget that ultimately discloses information to the attacker. Any CPU hardware that uses speculative execution and is vulnerable to Spectre v1 is likely affected by this variant. The discovery of Spectre was initially reported to Intel in 2016 by Daniel Gruss, a researcher at Graz University of Technology, focusing on the prefetch side-channel at the center of Spectre. However, Intel did not immediately act on this report, which led to the widespread exposure of the vulnerability two years later. Gruss suggested that if Intel had taken their report more seriously and conducted thorough investigations on different machines, the Spectre vulnerability could have been identified and addressed much earlier.
Description last updated: 2024-08-14T09:00:07.601Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Exploit
Hardware
Safari
Exploits
Encryption
Linux
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The iLeakage Vulnerability is associated with Spectre. iLeakage is a notable software vulnerability that impacts Apple devices, specifically through the Safari web browser. This flaw in software design or implementation allows attackers to exploit Safari and illicitly acquire data from users' devices. The iLeakage attack technique has raised significantis related to
4
The meltdown Vulnerability is associated with Spectre. Meltdown is a significant vulnerability, a flaw in software design or implementation that was discovered in 2018. This vulnerability, along with Spectre, exposed computer memory as an easy target for hackers to inject malicious code and steal data. These vulnerabilities could be triggered when softwis related to
4
The Spectre V2 Vulnerability is associated with Spectre. Spectre v2 is a software vulnerability that arises due to incorrect implementation of the Spectre v2 Simultaneous Multithreading (SMT) mitigations, specifically related to calling prctl with PR_SET_SPECULATION_CTRL. This flaw allows malicious code to exploit the shared branch history stored in the Cis related to
2
Source Document References
Information about the Spectre Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
4 months ago
CERT-EU
9 months ago
DARKReading
4 months ago
DARKReading
5 months ago
Checkpoint
5 months ago
DARKReading
7 months ago
DARKReading
8 months ago
DARKReading
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
DARKReading
9 months ago
DARKReading
9 months ago
CERT-EU
9 months ago
CERT-EU
10 months ago
CISA
10 months ago
CERT-EU
a year ago
CERT-EU
a year ago