Jump to content

Prevention of the installation of Meltdown/Spectre


hake

Recommended Posts

MBAE did not react while the patch was being installed.

I hope that MBAE will block any exploit needed to install Meltdown/Spectre spyware. I guess that the web browser or email attachment would be the route for an exploit to take.

Link to post
Share on other sites

I'm still waiting for an official answer to the original question.   Given that part of the problem is hardware/firmware related (requiring a BIOS/UEFI update), and part of the problem (to the best of my understanding) is based on the precise exploitation of "timing loops", I would hazard a guess that such vulnerabilities are beyond the scope of what MBAE monitors.   I'd be happy to learn I'm wrong about this.

Link to post
Share on other sites

11 hours ago, hake said:

MBAE did not react while the patch was being installed.

I hope that MBAE will block any exploit needed to install Meltdown/Spectre spyware. I guess that the web browser or email attachment would be the route for an exploit to take.

Good to know that Windows won't freak out. If MBAE does not block the exploit, then CIS would stop any unknown programs :D

Link to post
Share on other sites

I have read that an exploit can be performed by using JavaScript which works in a web browser to access memory.  JavaScript program can read data from the address space of the browser process running it.

Browser providers are working on mitigation updates: -
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/
https://www.chromium.org/Home/chromium-security/ssca

Edited by hake
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.