4 ms·
Somebody please correct me if I'm wrong, but I believe they're basically saying "These exploits do have the potential to read data."
by vhold 9y ago
Somebody please correct me if I'm wrong, but I believe they're basically saying "These exploits do have the potential to read data."
- int0x80 9y agoThere are not saying it explicitly, which they should.
- IshKebab 9y agoYeah, sort of "Don't worry I'm not going to shoot you in the torso, arms or legs."
- PeterisP 9y agoThey are - literally the sentence before that states "methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that are operating as designed".
- jsteemann 9y agoYep, seems to me they put much work into the statement "the exploits do not have the potential to corrupt, modify or delete data.". Which leaves open if (that?) reading of data is possible. And as this is not explicitly denied, we have to fear this is exactly what is possible.
- IshKebab 9y agoYes as far as we know it allows user-space code to read kernel memory, but not modify it. It affects Intel but not AMD according to them (not sure why Intel says otherwise). Details in this blog post from several months ago: https://cyber.wtf/2017/07/28/negative-result-reading-kernel-memory-from-user-mode/ https://cyber.wtf/2017/07/28/negative-result-reading-kernel-... They didn't get it to work but obviously someone else has.