← Back to context

Comment by ziofill

4 hours ago

But it supercharges what can be done once you get root, no?

AFAIK you can't usually replace CPU microcode, as it is signed. Seizing it here, in RW memory, really begs to toy with it: add instructions, edit them. Could you teach your CPU to understand RISC-V?

This is just one random idea. But altering PSP code is also interesting, to use it for your own purposes, or extract encryption keys / make it lie to clients (breaking DRM, for instance).

By a LOT. It would expose the data Windows keeps isolated using virtualization based security.

  • Does this mean the exploit can be used in a VM to get access to the host machine?

    • Not necessarily. A VM doesn't have a "real" DMA controller, and this exploit is specific to a family of real hardware CPUs.

      Its not to say that its not impressive, but its fairly isolated to a specific family of processors from 2013.

      1 reply →