Ethical Hacking News
A recent discovery in the field of computer security has revealed a potential vulnerability in modern encryption hardware, allowing attackers to bypass confidentiality guarantees in notionally secure computing environments. Researchers have identified a design flaw in scalable memory encryption hardware that enables access to protected memory, thus exposing sensitive data.
Researchers at KU Leuven, ETH Zurich, Durham University, and Google have identified a design flaw in scalable memory encryption hardware that enables access to protected memory. The vulnerability, dubbed "DDRop," exploits a weakness in the DDR5 memory bus protocol. The attack uses a custom-built "interposer" to interfere with DDR5 write operations and corrupt commands. The attack can be performed deterministically in under two minutes without crashing the machine. The attack can force any protected VM into debug mode and read out its private memory in plaintext. Intel and AMD have acknowledged the vulnerability and stated that it is out of scope for their cloud computing threat models. The discovery highlights the need for continued investment in secure computing infrastructure to prevent such attacks.
A recent discovery in the field of computer security has shed light on a potential vulnerability in modern encryption hardware, allowing attackers to bypass confidentiality guarantees in notionally secure computing environments. Researchers at KU Leuven, ETH Zurich, Durham University, and Google have identified a design flaw in scalable memory encryption hardware that enables access to protected memory, thus exposing sensitive data.
The vulnerability, dubbed "DDRop," exploits a weakness in the DDR5 memory bus protocol, which is designed to prevent address-aliasing attacks. However, the researchers have found that the protocol's redesigned command bus prevents the use of a specific attack vector known as "Battering RAM." In contrast, the DDRop attack uses a custom-built "interposer" – a small, custom-designed circuit board that sits between the processor and a memory module – to interfere with DDR5 write operations.
The interposer, costing under $200, corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory. This allows the protected virtual machine (VM) to continue computing on old, decrypted data, thereby compromising the confidentiality guarantees made by cloud service providers. The attack can be performed deterministically in under two minutes without crashing the machine.
According to the researchers, the DDRop attack can force any protected VM into debug mode and read out its private memory in plaintext. Furthermore, writing to critical TDX metadata structures enables forged attestation reports, allowing the attacker to masquerade as a trusted VM. The attack succeeds without relying on software bugs or exploiting specific hardware vulnerabilities.
The researchers have developed a proof-of-concept attack on a current Intel TDX server, demonstrating the feasibility of the DDRop attack. They have also developed a similar attack on DDR4, highlighting the need for continued research and development in this area.
Intel and AMD, both of which use the affected scalable memory encryption hardware, have acknowledged the vulnerability and stated that it is out of scope for their cloud computing threat models. However, the researchers emphasize that there is currently no easy fix for the vulnerability and that no simple software or hardware patch can address the root cause.
The discovery of the DDRop vulnerability underscores the ongoing challenges faced by cloud service providers and the importance of continued investment in secure computing infrastructure. As the use of scalable memory encryption hardware becomes increasingly widespread, it is essential to address potential vulnerabilities and develop effective countermeasures to prevent such attacks.
In conclusion, the DDRop vulnerability highlights the need for vigilance in the development and implementation of secure computing infrastructure. As researchers continue to uncover new vulnerabilities in modern encryption hardware, it is crucial that industry leaders and policymakers take proactive steps to address these issues and ensure the confidentiality and integrity of sensitive data.
A recent discovery in the field of computer security has revealed a potential vulnerability in modern encryption hardware, allowing attackers to bypass confidentiality guarantees in notionally secure computing environments. Researchers have identified a design flaw in scalable memory encryption hardware that enables access to protected memory, thus exposing sensitive data.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Hardware-Device-Can-RAM-into-Encrypted-Memory-Expose-Your-Data-ehn.shtml
https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377
Published: Mon Sep 14 14:18:50 2026 by llama3.2 3B Q4_K_M