Skip to content
It's interesting

The new module for $200 provides access to protected memory in Intel and AMD processors

AuthorEditorial team 15-09-2026, 12:36 96
The new module for $200 provides access to protected memory in Intel and AMD processors
Advertising
In brief
  • Researchers found an architectural flaw in the memory protection of Intel and AMD.
  • The new DDRop module (≈$200) can bypass TDX, SGX, and SEV-SNP with physical access.
  • Manufacturers have acknowledged the vulnerability but do not plan to release patches.

A group of international cybersecurity experts has identified a fundamental flaw in the architecture of modern memory encryption systems. The problem arises from the fact that protected memory areas can be read if an attacker connects a special device between the processor and the DDR5 modules.

How the DDRop module works

A hardware intermediary developed by researchers, called DDRop, is embedded in the memory bus and alters write operations without noticeable impact on performance. After the intervention, the virtual machine continues to operate using outdated data selected by the attacker and is unaware of their inaccuracy.

The attack requires only physical access to the server, making the scheme relevant in scenarios where cloud providers promise clients complete confidentiality of computations. Special services may also exploit such a vulnerability to gain access to confidential information.

Bypassing trusted computing mechanisms

The device is capable of disrupting the operation of protection mechanisms such as Intel TDX, scalable SGX, and AMD SEV-SNP, which are used in trusted computing environments (TEE). According to the project authors, injecting specially crafted entries into the page table transitions the protected virtual machine into debug mode, allowing the contents of its private memory to be read in plaintext.

Furthermore, altering critical TDX metadata makes it possible to forge attestation reports, so a virtual machine with an implanted backdoor continues to appear trustworthy to a remote user.

A feature of DDRop is the ability to modify DDR5 bus traffic without reducing data transfer rates, as well as the fact that this is the first known attack that allows compromising the trusted management interface of TDX without exploiting software vulnerabilities.

Manufacturer's Response

Intel and AMD have confirmed the existence of the vulnerability, but stated that it does not fall within their threat model for cloud services and do not plan to release patches – neither software nor hardware. According to them, the problem arose due to the abandonment of certain mechanisms capable of ensuring the uniqueness and relevance of each version of encrypted data when working with large volumes of memory.

The lack of a ready solution raises questions about the security of cloud platforms that rely on TDX, SGX, and SEV-SNP technologies to protect confidential computations. So far, the only practical way to ensure protection remains the physical isolation of servers and access control to the hardware.

The discovery of the vulnerability underscores the need to reassess approaches to data protection in the cloud and stimulates discussion of more reliable encryption methods that will not be vulnerable to such hardware interventions.

Source: 3DNews

How useful is the material?Evaluation helps us choose topics
00 ratings
Analytics

Story statistics

96views
0comments
2min read
36 / 55rank in section, last 30 days

Discussion

No one has spoken yet — be the first.

Comments are written by participants Log in to the site — it's free and takes a minute. Comments are moderated.
Log in
Advertising

What searches this page answers