$ techbeacon▋
Threats

Researchers Unveil DDRop Attack Undermining Intel and AMD Confidential Computing

Researchers Unveil DDRop Attack Undermining Intel and AMD Confidential Computing

Security researchers have revealed a novel hardware exploit named DDRop that compromises the memory protection schemes employed by Intel's Trusted Execution Environment (TDX) and AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV‑SNP). The technique works by silently discarding write operations to a server's RAM, causing the processor to continue reading previously encrypted data as if it were current, effectively breaking the confidentiality guarantees of these platforms.

Both TDX and SEV‑SNP are cornerstone technologies for confidential computing, a model that seeks to keep data protected not only at rest and in transit but also while it is being processed. They achieve this by encrypting memory contents and binding the encryption keys to the hardware, so that even a compromised operating system cannot access clear‑text data. This approach has been widely adopted by cloud providers to isolate tenant workloads and to meet regulatory requirements for data privacy.

The DDRop attack subverts this model by targeting the write path. By forcing the memory controller to drop specific write transactions without alerting the CPU, the exploit ensures that stale ciphertext remains in place. When the processor later reads that location, it decrypts the old value, allowing an attacker to induce inconsistencies or extract information that should have been overwritten. Because the drop occurs at the hardware level, traditional software‑based integrity checks are bypassed.

The discovery raises immediate concerns for cloud infrastructure that relies on these hardware protections. Multi‑tenant environments, where different customers share the same physical server, could be exposed to data leakage or manipulation if an adversary can trigger the write‑dropping behavior. The attack also challenges the broader trust model of confidential computing, prompting providers to reassess the robustness of their isolation guarantees.

In response, the security community is urging chipset manufacturers to investigate firmware updates or microcode patches that can detect and prevent unauthorized write suppression. Vendors have indicated that mitigation strategies are under review, though timelines remain uncertain. Meanwhile, experts advise organizations using confidential computing to stay informed about forthcoming patches and to consider additional layers of verification where feasible. The DDRop revelation underscores the ongoing arms race between hardware designers and attackers, highlighting the need for continuous scrutiny of even the most trusted security primitives.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related