【資訊安全】存在於中央處理器之「Meltdown」「 Spectre」安全漏洞

Google Project Zero 團隊於2018/01/03 公佈於中央處理器底層架構之
「Meltdown」「Spectre」安全漏洞。

「Meltdown」能使駭客進入系統核心記憶體,傾印出記憶體內的資訊。
示範影片:Meltdown in Action: Dumping memory
https://www.youtube.com/watch?v=bReA1dvGJ6Y

「Spectre」能使駭客騙過應用程式安全檢查的程序,竊取資訊。

影響範圍:
個人電腦、行動裝置及雲端架構主機。
採用INTEL、AMD、ARM CPU皆為影響範圍。

Intel:
Intel Atom Processor A、C、E、x3、Z Series
Intel Core i3、i5、i7、M processor (45nm and 32nm)
Intel Celeron&Pentium Processor J、N Series
Intel 2~8 generation Intel® Core™ processors

ARM:Cortex R7、R8、A8、A9、A15、A17、A57、A72、A73、A75。
(智慧型手機、平板電腦等行動裝置)

受影響作業系統廠商:
Google、Linux Kernel、Microsoft,以及Mozilla。

建議措施:
微軟及Linux已分別釋出安全更新檔「KB4056892」「KB4056897」「KB4056898」及「KAISER」
Windows 10已開放自動更新,Windows 7目前僅提供手動安裝更新。

Windows 7、10 安全更新檔已放置於校園授權軟體FTP中。
亦或自行前往官方網站下載。

Windows 7 - KB4056897
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4056897

Windows 8.1 - KB4056898
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4056898

Windows 10 - KB4056892
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4056892

===

Windows Server 2008 R2 - KB4056897
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4056897

Windows Server 2012 R2 - KB4056898
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4056898

Windows Server 2016 (1709) - KB4056892
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4056892

駭客須於目標系統上執行惡意程式,目前無單一修補程式解決已知相關變種漏洞,請使用者於安全性更新發佈時儘速更新。

相關參考資料:
Intel Security Center:
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr

Google Security:
https://security.googleblog.com/2018/01/more-details-about-mitigations-for-cpu_4.html

科技新報:
https://technews.tw/2018/01/05/win-10-macos-linux-update/
https://technews.tw/2018/01/05/how-to-protect-yourself-from-meltdown-and-spectre-cpu-flaws/