Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-11091

Description

Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

POC

Reference

- https://kc.mcafee.com/corporate/index?page=content&id=SB10292

- https://seclists.org/bugtraq/2019/Jun/28

- https://seclists.org/bugtraq/2019/Jun/36

- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/alyaparan/Spectre-Meltdown

- https://github.com/amstelchen/smc_gui

- https://github.com/codexlynx/hardware-attacks-state-of-the-art

- https://github.com/dineshpinto/awesome-tee-blockchain

- https://github.com/edsonjt81/spectre-meltdown

- https://github.com/es0j/hyperbleed

- https://github.com/giterlizzi/secdb-feeds

- https://github.com/hwroot/Presentations

- https://github.com/j1nh0/nisol

- https://github.com/j1nh0/pdf

- https://github.com/j1nh0/pdf_esxi

- https://github.com/j1nh0/pdf_systems

- https://github.com/kali973/spectre-meltdown-checker

- https://github.com/kaosagnt/ansible-everyday

- https://github.com/kin-cho/my-spectre-meltdown-checker

- https://github.com/merlinepedra/spectre-meltdown-checker

- https://github.com/merlinepedra25/spectre-meltdown-checker

- https://github.com/nsacyber/Hardware-and-Firmware-Security-Guidance

- https://github.com/savchenko/windows10

- https://github.com/speed47/spectre-meltdown-checker

- https://github.com/timidri/puppet-meltdown