DDRop Hardware Attack Exploits Memory Encryption Flaws in Intel TDX and AMD SEV-SNP
A new hardware attack called DDRop exploits memory encryption flaws in Intel TDX and AMD SEV-SNP, allowing attackers to silently overwrite encrypted data by inserting a low-cost interposer device. The vulnerability undermines confidential computing protections in cloud environments, with no simple software patch available due to hardware design limitations.
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current.
The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit
*** END OF TRANSMISSION ***