Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs 

Intel and AMD have published advisories after academics disclosed details of the new TEE.fail attack method.

Chipmaker Patch Tuesday

A team of academic researchers has disclosed the details of a new attack method that can be used to break CPU-based security technologies from Intel and AMD by targeting DDR5 memory.

The attack method, named TEE.fail, was discovered by researchers from Purdue University and Georgia Institute of Technology. 

The attack requires physical access to the targeted system and involves placing a device named an interposer between the computer’s CPU and memory in an effort to analyze DRAM bus traffic.

An attacker can then use the captured data to extract cryptographic keys from Intel TDX and AMD SEV-SNP trusted execution environment (TEE) implementations. In addition, a hacker can extract attestation keys that can be leveraged to compromise Nvidia’s GPU Confidential Computing, which allows attackers to run AI workloads without any TEE protections, the researchers explained. 

These confidential computing technologies, used for data centers and cloud computing, are designed to protect code and data from attackers who have compromised the host system, and even from malicious insiders. 

The TEE.fail attack involves soldering the interposer to the DIMM. The interposer built by the researchers, for which they have made available schematics, costs under $1,000 if off-the-shelf electronic components are used. 

Advertisement. Scroll to continue reading.

TEE.fail is similar to the recently disclosed WireTap and Battering RAM attacks, which also involved using an interposer to capture valuable data from memory. 

However, there are some significant differences. WireTap and Battering RAM only worked against DDR4 memory, while TEE.fail targets DDR5.

“The difference is critical, as TEE.fail can be used to attack the latest TEE offerings by Intel and AMD, namely Intel TDX and AMD SEV-SNP with Ciphertext Hiding, which offer confidential virtual machines (CVMs),” the researchers explained. “As CVMs are used for the trust anchor in Nvidia’s GPU confidential computing, we show how our attack also breaks GPU attestation.”

Both Intel and AMD have published advisories in response to the TEE.fail research. However, as in the case of WireTap and Battering RAM, the chip giants said attacks requiring physical access to the targeted system are not in scope of their products’ threat model.

Related: New CounterSEVeillance and TDXDown Attacks Target AMD and Intel TEEs

Related: RMPocalypse: New Attack Breaks AMD Confidential Computing

Related: VMScape: Academics Break Cloud Isolation With New Spectre Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.