This is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?
This is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?
Reaching into ring -2 or the TPM allows privilege escalations past traditional "root permissions" and lets attackers defeat the sort of tamper protection that's designed to make escalations to local root manageable. Wipe-resistant malware, falsified cryptographic attestations, all sorts of fun.
This is more about getting at the code that device manufacturers attempt to hide from the end user. Platform keys, secure enclaves, etc...
Yep, I believe so
But it supercharges what can be done once you get root, no?
By a LOT. It would expose the data Windows keeps isolated using virtualization based security.
Does this mean the exploit can be used in a VM to get access to the host machine?
Not necessarily. A VM doesn't have a "real" DMA controller, and this exploit is specific to a family of real hardware CPUs.
Its not to say that its not impressive, but its fairly isolated to a specific family of processors from 2013.
Yep.