IndyTek Consulting
  • Home
  • Services
  • Projects
  • Business Partners
  • Tech Blog
  • Home
  • Services
  • Projects
  • Business Partners
  • Tech Blog

Spectre / Meltdown CPU Flaw

1/12/2018

0 Comments

 
Our information security team is aware of several related security bulletins for vulnerabilities identified with “speculative execution functionality” of multiple vendors’ central processing units (CPU). As of this writing, there are three known variants:

CVE-2017-5715 - Branch target injection (SPECTRE)
CVE-2017-5753 - Bounds check bypass (SPECTRE)
CVE-2017-5754 - Rogue data cache load (MELTDOWN)

Review the reference information below to become more familiar with these vulnerabilities and validate that any software applications not managed by GUTS have the latest patches applied.  GUTS additionally recommends that all customers verify that all systems in use within their organizations are verified as having the latest patches applied – including desktops and laptops.

Reference Information
Meltdown Technical Deep Dive PDF
Spectre Technical Deep Dive PDF
VMware Security Response
CERT Vulnerability Notice
CERT Exploit Notice
Google Project Zero Analysis
Microsoft Security Notice
WIRED Magazine news article
AnandTech news article



0 Comments

    Author

    Sr. Consultant - IndyTek Consulting

    Archives

    June 2019
    November 2018
    August 2018
    May 2018
    April 2018
    February 2018
    January 2018
    May 2017

    Categories

    All
    Internet Security
    Security / Threat Outlook

    RSS Feed

Powered by Create your own unique website with customizable templates.