← Back to Tech & Science

New Hardware Vulnerability DDRop Compromises Intel and AMD Confidential Computing

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

BRUSSELS (AP) — A critical hardware vulnerability dubbed DDRop has been disclosed that undermines memory protection in confidential computing systems powered by Intel and AMD processors, allowing attackers to silently drop writes to server memory. The flaw affects the Trusted Domain Extensions (TDX) architecture from Intel and Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) from AMD, technologies designed to isolate sensitive data even from cloud providers.

Researchers from KU Leuven, ETH Zurich, Durham University, and Google announced the discovery on Monday. The vulnerability exploits a mechanism within the memory controller that permits an adversary with physical access to a server to manipulate how data is written to RAM. By intercepting and discarding write operations without triggering error signals, attackers can alter the state of protected enclaves or exfiltrate cryptographic keys while the system continues to operate normally.

Confidential computing relies on hardware-based isolation to ensure that data remains encrypted even when processed in untrusted environments like public clouds. The DDRop attack bypasses these safeguards by targeting the physical interface between the processor and memory modules, rendering software-level protections ineffective against a determined attacker with local access. The researchers demonstrated that the exploit works across various server configurations currently deployed globally.

The disclosure highlights a significant gap in the hardware security assumptions underpinning modern cloud infrastructure. Unlike previous vulnerabilities that required software exploits or remote code execution, DDRop necessitates physical proximity to the target machine. However, this requirement does not eliminate the risk for data centers where maintenance personnel or malicious insiders could potentially gain access to server racks.

Intel and AMD have acknowledged the issue and are working on firmware updates and hardware revisions to mitigate the threat. The companies stated that no evidence exists of DDRop being exploited in the wild, but they urged customers to review their physical security protocols immediately. Google, which utilizes these confidential computing technologies extensively across its cloud services, confirmed it is implementing countermeasures to protect customer workloads.

The attack vector raises questions about the long-term viability of hardware-based trust models when physical access cannot be guaranteed. While the researchers provided detailed technical specifications to aid in patching, the fundamental design flaw suggests that future generations of processors may require architectural changes to prevent similar memory manipulation techniques. Security experts are now assessing whether other confidential computing frameworks face analogous risks from physical layer attacks.

As cloud providers race to deploy patches, the incident serves as a stark reminder that hardware vulnerabilities can persist undetected for years before being exposed. The full scope of affected systems remains under investigation, with manufacturers expected to release comprehensive guidance in the coming weeks.

Discussion

0 / 2000