New CPU Vulnerability Exploits System Management Mode
TL;DR. A newly identified CPU vulnerability allows a malicious core to discreetly exit System Management Mode while other cores remain within it, creating a critical window for potential privilege escalation and system compromise through various attack vectors. - A CPU vulnerability was discovered where one core can exit System Management Mode independently. - Other CPU cores remain in System Management Mode during this event. - This allows for potential privilege escalation and system compromise.
- The vulnerability hinges on a single, uninterruptible instruction lasting over one second, bypassing a 1-second synchronization timeout.
- System Management Mode (SMM) is a highly privileged x86 CPU environment designed for secure background operations.
- Successful exploitation allows unauthorized code execution or privilege escalation due to core synchronization failure.
- This hardware-level flaw affects the fundamental security model of x86 processors.