• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

ZombieLand came again in a new variant and its TPM-FAIL vulnerabilities caused a huge risk

{{postValue.id}}

A new variant of ZombieLoad that exploits the Transactional Synchronization Extensions (TSX) Asynchronous Abort operation in Intel processors for both older as well as recent processors including Cascade Lake architecture, was recently reported by a group of university researchers. The said researchers were said to have helped find Spectre and Meltdown flaws. This flaw is also called CVE-2019-11135. There are two flaws, CVE-2019-11090 that affects Intel fTPM andCVE-2019-16863 that affects STMicroelectronics TPM chip namely, and together they are called as TPM-Fail vulnerabilities.

It allows attackers to retrieve cryptographic keys protected inside Trusted Platform Module (TPM) chips which are part of many modern processors. The research team has also published a proof-of-concept exploit on Github. The affected chips are deployed in billions of devices including desktops, laptops, smartphones, servers, and Internet-of-Things (IoT) devices.

Using this vulnerability, local attackers or malware running on a vulnerable machine can snoop on processor cores and steal sensitive data from the operating system kernel. An attacker with access to the system can lift passwords, keys, and more from other running software.

The TPM-Fail vulnerabilities, on the other side, can be exploited by an adversary to leverage a timing-based side-channel attack to recover cryptographic keys.

Tags:
isaac
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Isaac ?
How to run windows application in linux

I need to run the windows application in my Linux machine, instead of installing from yum repo or any other repos. How to do that..??

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.