Sinisterly
Meltdown Patch Opened Worse Vulnerability In Windows 7 - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: General (https://sinister.ly/Forum-General)
+--- Forum: World News (https://sinister.ly/Forum-World-News)
+--- Thread: Meltdown Patch Opened Worse Vulnerability In Windows 7 (/Thread-Meltdown-Patch-Opened-Worse-Vulnerability-In-Windows-7)



Meltdown Patch Opened Worse Vulnerability In Windows 7 - mothered - 03-29-2018

Greetings to all,

Further to patching the Meltdown vulnerability back In January of this year, It somewhat defeated It's purpose by creating a bigger Issue for Windows 7 users.

Quote:"[The patch] stopped Meltdown but opened up a vulnerability way worse...It allowed any process to read the complete memory contents at gigabytes per second, oh -- it was possible to write to arbitrary memory as well"

"No fancy exploits were needed. Windows 7 already did the hard work of mapping in the required memory into every running process. Exploitation was just a matter of read and write to already mapped in-process virtual memory. No fancy APIs or syscalls required -- just standard read and write,"

Impressive. @phyrrus9, you'll like this.

Source.


RE: Meltdown Patch Opened Worse Vulnerability In Windows 7 - Pikami - 03-29-2018

Strange that it only effects win7
I wouldn't be surprised to see this thing in win8 and win10 in a couple of days/weeks


RE: Meltdown Patch Opened Worse Vulnerability In Windows 7 - mothered - 03-29-2018

(03-29-2018, 10:48 AM)Pikami Wrote: Strange that it only effects win7
I wouldn't be surprised to see this thing in win8 and win10 in a couple of days/weeks

Agree.

The report states:
Quote:The flaw does not affect Windows 10 or Windows 8, according to Frisk.

That's according to "Frisk". But has It actually affected Windows 8 & 10 (without anyone's knowledge) Is the question.


RE: Meltdown Patch Opened Worse Vulnerability In Windows 7 - Bish0pQ - 03-29-2018

Seems like it's time to get rid of my whole Windows installation and finally switch to Linux. On a serious note though, that really sucks for them, that's some bad publicity again.


RE: Meltdown Patch Opened Worse Vulnerability In Windows 7 - phyrrus9 - 03-29-2018

(03-29-2018, 10:32 AM)mothered Wrote: Greetings to all,

Further to patching the Meltdown vulnerability back In January of this year, It somewhat defeated It's purpose by creating a bigger Issue for Windows 7 users.

Quote:"[The patch] stopped Meltdown but opened up a vulnerability way worse...It allowed any process to read the complete memory contents at gigabytes per second, oh -- it was possible to write to arbitrary memory as well"

"No fancy exploits were needed. Windows 7 already did the hard work of mapping in the required memory into every running process. Exploitation was just a matter of read and write to already mapped in-process virtual memory. No fancy APIs or syscalls required -- just standard read and write,"

Impressive. @phyrrus9, you'll like this.

Source.

I saw this a few days ago and complained about it in the Discord. At this point, Intel just needs to throw in the towel, 2018 has been a terrible year for them.


RE: Meltdown Patch Opened Worse Vulnerability In Windows 7 - Mr.Kurd - 03-29-2018

(03-29-2018, 05:26 PM)Bish0pQ Wrote: Seems like it's time to get rid of my whole Windows installation and finally switch to Linux. On a serious note though, that really sucks for them, that's some bad publicity again.

too late Smile


RE: Meltdown Patch Opened Worse Vulnerability In Windows 7 - mothered - 03-30-2018

(03-29-2018, 09:26 PM)phyrrus9 Wrote:
(03-29-2018, 10:32 AM)mothered Wrote: Greetings to all,

Further to patching the Meltdown vulnerability back In January of this year, It somewhat defeated It's purpose by creating a bigger Issue for Windows 7 users.

Quote:"[The patch] stopped Meltdown but opened up a vulnerability way worse...It allowed any process to read the complete memory contents at gigabytes per second, oh -- it was possible to write to arbitrary memory as well"

"No fancy exploits were needed. Windows 7 already did the hard work of mapping in the required memory into every running process. Exploitation was just a matter of read and write to already mapped in-process virtual memory. No fancy APIs or syscalls required -- just standard read and write,"

Impressive. @phyrrus9, you'll like this.

Source.

I saw this a few days ago and complained about it in the Discord. At this point, Intel just needs to throw in the towel, 2018 has been a terrible year for them.

And at the time of the first (Meltdown) vulnerability, the year had just started.

The third month Is coming to a close, and subsequent vulnerabilities from Meltdown have emerged. What will the next 9 months hold for Intel? It remains to be seen.