Response to reports on Spectre-NG
Technical Articles ID:
KB90619
Last Modified: 2022-11-01 15:09:14 Etc/GMT
Last Modified: 2022-11-01 15:09:14 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
Response to reports on Spectre-NG
Technical Articles ID:
KB90619
Last Modified: 2022-11-01 15:09:14 Etc/GMT Environment
SIEM Enterprise Security Manager (ESM) 11.x
Summary
On May 21, 2018, new variants of the side-channel central processing unit (CPU) hardware vulnerabilities known as Variant 3a (Rogue System Register Read – CVE-2018-3640) is a vulnerability that might allow an attacker with local access to speculatively read system parameters via side-channel analysis and obtain sensitive information. Variant 4 (Speculative Store Bypass – CVE-2018-3639) is a vulnerability that exploits "speculative bypass". When exploited, Variant 4 could allow an attacker to read older memory values in a CPU stack or other memory locations. Although implementation is complex, this side-channel vulnerability could allow less privileged code to:
For malware best practices, see KB89805 - How to respond to a ransomware infection. Subscribe to this article for updates. To receive email notification when this article is updated, click Subscribe on the right side of the page. You must be logged on to subscribe.
Solution
These issues are resolved in SIEM 10.3.3 (or later) and SIEM 11.1.0 (or later). NOTE: Trellix strongly recommends that customers upgrade to the latest version of the product for continued support. For details about product versions, see KB82516 - Supported platforms for Enterprise Security Manager. Affected ProductsLanguages:This article is available in the following languages: |
|