Monday, May 12, 2025
HomeVulnerabilityIntel Paid $100,000 Reward to Researchers who Discovered Spectre 1.1, 1.2 CPU...

Intel Paid $100,000 Reward to Researchers who Discovered Spectre 1.1, 1.2 CPU Level Vulnerability

Published on

SIEM as a Service

Follow Us on Google News

Intel rewarded $100,000 for two security researchers to find the CPU Spectre level critical vulnerability which leads to leak confidential information through microarchitectural side channels.

Newly discovered spectre level vulnerabilities are catogorised as Spectre 1.1, a new Spectre-v1 and Spectre 1.2.

Previously discovered highly critical vulnerabilities Spectre and Meltdown have been made a huge impact in IT sectors and the attack works on mobile devices, personal computers and cloud infrastructure depends on the cloud providers.

- Advertisement - Google News

Spectre and Meltdown flaw allow an attacker to steal the data that currently processed on the computer it includes the process of personal photos, Emails, Password manager, instant messages and sensitive documents.

Same as old spectre vulnerabilities, These 2 Spectre 1.1, Spectre 1.2 also affect the CPU which leads to excute the malicious process and take over the previously secured CPU memory.

Both of the attacks leverage the “speculative execution” technique which is used by most modern CPUs to optimize performance.

Spectre 1.1

Newly discovered Spectre 1.1(Bounds check bypass CVE-2017-5753) create speculative buffer overflows by leverages speculative stores. same as traditional buffer overflow, it  can modify data and code pointers.

In this case reserarchers said Data-value attacks can bypass some Spectre-v1 mitigations, either directly or by redirecting control flow.

Attacker can ale to  perform arbitrary speculative code execution using Control-flow attacks and also it bypass the mitigation that was applied on precious speculative-execution attacks in Spectre 1.0.

Intel and ARM has been acknowledged for their vulnerable CPU’S and the AMD didn’t release any statment in this regards.

Spectre 1.2

Researchers said, Spectre1.2(Bounds check bypass on stores – CVE-2018-3693) vulnerability allow to by the read-only Protection and , speculative stores are allowed to overwrite read-only data, code pointers, and code metadata, including vtables.

Also the issue could be exploited by an attacker to bypass the Read/Write PTE flags and write code directly in read-only data memory.

According to the Researchers, We advise users to refer to more user-friendly vendor recommendations for mitigations against speculative buffer overflows or available patches.

MicrosoftRed Hat, Oracle have released security advisories, confirming that they are investigating the issues and potential effects.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Open Source Linux Firewall IPFire 2.29 – Core Update 194 Released: What’s New!

IPFire, the powerful open-source firewall, has unveiled its latest release, IPFire 2.29 – Core...

Threat Actors Leverage DDoS Attacks as Smokescreens for Data Theft

Distributed Denial of Service (DDoS) attacks, once seen as crude tools for disruption wielded...

20-Year-Old Proxy Botnet Network Dismantled After Exploiting 1,000 Unpatched Devices Each Week

A 20-year-old criminal proxy network has been disrupted through a joint operation involving Lumen’s...

“PupkinStealer” – .NET Malware Steals Browser Data and Exfiltrates via Telegram

A new information-stealing malware dubbed “PupkinStealer” has emerged as a significant threat to individuals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

VMware Tools Vulnerability Allows Attackers to Modify Files and Launch Malicious Operations

Broadcom-owned VMware has released security patches addressing a moderate severity insecure file handling vulnerability...

Mitel SIP Phone Flaws Allow Attackers to Inject Malicious Commands

A pair of vulnerabilities in Mitel’s 6800 Series, 6900 Series, and 6900w Series SIP...

PoC Code Published for Linux nftables Security Vulnerability

Security researchers have published proof-of-concept (PoC) exploit code for CVE-2024-26809, a high-severity double-free vulnerability in...