Intel CPU Rootkit to be released
March 18th, 2009Tomorrow at 12pm EST Joanna Rutkowska and Loic Duflot are publishing a paper and actual exploit code that works against Intel cache mechanisms. These attacks will allow privileged escalation in SMM (System Management Mode) space and capable of deploying a rootkit that can take complete control of the machine. SMM space is out of reach of operating systems and this attack cannot be detected or protected with any current form of software anti-virus protection. SMM space is available on all Intel CPUs from as far back as the Intel 386.
This exploit has been reported to Intel on numerous occasions over the last few years. Loic reported it 3-4 months prior back in October and Intel’s own employees had made mentioned of it in documents as far back as 2005. So far to date, Intel has not provided any resolution to this vulnerability and is this is the main reason behind Joanna and Loic going the full disclosure route. Joanne mentions on her blog “If there is a bug somewhere and if it stays unpatched for enough time, it is almost guaranteed that various people will (re)discover and exploit it, sooner or later.”
Intel did alert CERT back in October when Loic reported his findings, this was tracked under Issue VU#127284.
You will find full details published at Joanna’s website Invisible Things Kernel Security Blog
Currently, there is no defense to this threat outside of using AMD or Virtualization, or is there Intel?
TagsAuthor: Christopher


March 29th, 2009 at 9:10 pm
I’d like to understand this vulnerability a little better. It seems that some executing code could, by abusing the SMM space, take control of a system. But this execution itself would already have to be on the targeted system, no? Do you think “drive-by” infection with something like this is possible?
April 3rd, 2009 at 7:52 pm
This threat follows the same rules as other malware regarding infection. You have to load/download an executable file before your system can be compromised. Like rootkits, this may be the last time you will be able to detect or remove this threat using standard anti virus software as even the operating system has no knowledge of the files and processes.
May 16th, 2009 at 5:12 pm
Hey thanks for the information..
Work from home
March 31st, 2010 at 10:29 pm
[...] of the protocol (passwords in cleartext, for … Mail (will not be published) (required) … Intel CPU Rootkit to be released – Enterprise Security UpdateJoe Poniatowski Says: March 29th, 2009 at 9:10 pm. I'd like to understand this vulnerability a [...]