funsec mailing list archives

RE: Description of the Intel CPU bugs


From: "Larry Seltzer" <Larry () larryseltzer com>
Date: Thu, 28 Jun 2007 14:26:05 -0400

Yes, flashing your own microcode into the CPU would be the ultimate
pwn-the-box, 
except (a) you'd still have to arrange for it to get re-flashed at
power-on, and 
(b) the format is incredibly undocumented, and dependent on the exact
internal 
design, down to processor family and probably stepping (the current
microcode 
update from Intel covers 125, yes 125, different CPUs).  So unless you
have docs 
for what bit 57 of a format-7 microcode control word for a T6500
processor does, 
you will almost certainly just lock the damned thing up and require a
power 
cycle... ;)

So the one Microsoft update has all of the microcode for all of the
Intel CPUs in it?

Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blogs.eweek.com/cheap_hack/
Contributing Editor, PC Magazine
larryseltzer () ziffdavis com 

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: