Intel Cascade Lake CPUs hit by new security flaw

(Image credit: Shutterstock.com / Nicescene)

The security of Intel hardware has once again been called into question after another serious security vulnerability was uncovered.

Following the well-publicised issues surrounding Meltdown and Spectre, a new flaw has been uncovered that could allow hackers to gain entry to devices powered by Intel CPUs.

However the affected systems don't feature older generations of Intel hardware, but instead are those powered by the latest Cascade Lake CPUs, with both 10th Gen Intel Core and 2nd Generation Intel Xeon processors affected.

Flaw

The vulnerability, named ZombieLoad 2, or TSX Asynchronous Abort, targets the Transactional Synchronization Extensions (TSX) feature in Intel processors. Speculative execution typically looks to boost the performance of the CPU by running instructions in advance of knowing if they are needed or not.

ZombieLoad attacks were first detected in May 2019, when it was discovered they could use malicious program to steal sensitive data from memory locations that normally they could not access.

Now, a second generation, ZombieLoad 2, has been found to be able to get around the defences put in place after the initial attacks were detected and steal sensitive data from the operating system kernel or other processes.

Intel has documented the full extent of the flaw in a blog post, noting that the issue should be fixed through Microsoft's latest November 2019 Patch Tuesday updates, with Intel recommending users patch their systems immediately.

Via BleepingComputer

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead