SWAPGS Speculative Execution Vulnerability for Intel CPUs Disclosed, Microsoft Releases Windows 10 Patch

Intel CPUs have once again been found to be vulnerable to a speculative execution exploit

Advertisement
By Jamshed Avari | Updated: 7 August 2019 17:52 IST
Highlights
  • The flaw was discovered a year ago and has just been publicly disclosed
  • Microsoft released a patch for the vulnerability in July
  • AMD says its CPUs are not affected by this specific flaw

Security vendor Bitdefender has disclosed details of a new speculative execution security vulnerability in Intel CPUs dating back to 2012, which could be used to steal sensitive information including passwords from a computer. The newly discovered issue, named SWAPGS, could also negate all the patches so far released for the infamous Spectre and Meltdown flaws. According to Bitdefender, the issue was first discovered over a year ago, and the company has been working with Intel and other ecosystem stakeholders in order to minimise its impact. Public disclosure was withheld till just now, at the ongoing Black Hat security conference, where Bitdefender has released a detailed whitepaper on its research.

The flaw follows the highly publicised Spectre and Meltdown speculative execution vulnerabilities, as well as other similar flaws that have been discovered since. All Intel CPUs starting with the Ivy Bridge generation, first released in 2012, are particularly affected by these issues due to the fundamental design of their architecture. AMD has released a statement saying that it believes its products are unaffected, though this has not yet been confirmed by third-party research.

Advertisement

Speculative execution refers to a CPU's way of speeding up operations by pre-emptively running instructions that might be needed in the future, in order to make sure that the CPU pipeline is not waiting for data and can successfully utilise all its resources simultaneously rather than waiting for one instruction to complete before its result can be applied to further calculations. Security flaws arise when the CPU is allowed to speculatively execute instructions that require secure data, which should only be accessed when sufficient privileges are granted. Attackers can craft instructions that intercept that data while it is being accessed in this manner.

The SWAPGS instruction is used by Intel CPUs when switching between the secure (kernel mode) and open (user mode). A sophisticated attacker could exploit the way that Windows issues instructions to intercept sensitive data that should have been in the privileged kernel memory space.

Advertisement

In a statement published by The Inquirer, Intel has stated: "Intel, along with industry partners, determined the issue was better addressed at the software level and connected the researchers to Microsoft. It takes the ecosystem working together to collectively keep products and data more secure, and this issue is being coordinated by Microsoft."

Microsoft released a security patch addressing this issue in July 2019 without publicising it, but has now published its own disclosure. This patch is recommended, since previous patches for Spectre and Meltdown, amongst other similar issues, will not protect against SWAPGS.

Advertisement

Red Hat has also published an advisory stating that it does not believe that SWAPGS can be exploited on operating systems based on the Linux kernel, but users can update and reboot their systems just in case.

Bitdefender has published a detailed whitepaper on the SWAPGS vulnerability, in which it states that the AMD CPUs it tested were not affected, and that it doesn't believe that other architectures including ARM will be vulnerable, though there is a possibility that other equivalent exploits might exist.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  2. Oppo K14 5G Debuts With 7,000mAh Battery at This Price in India
  3. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  4. Vivo T5x 5G Goes Official in India With 7,200mAh Battery
  5. Best Mobiles Under Rs. 25,000 in India
  6. Oppo Find N6 Launched With Snapdragon 8 Elite Gen 5 SoC, 6,000mAh Battery
  7. Samsung Galaxy M17e 5G Debuts With 6,000mAh Battery at This Price in India
  8. Oppo Watch X3 Goes Official With This Price Tag
  9. Apple Reportedly Increases Foldable iPhone Panel Orders to 20 Million
  10. Samsung Could Equip Galaxy Z Fold 8, Wide Fold With These Batteries
  1. Instagram Rolls Out New AI Voice Effects For Voice Notes With Eight Filters
  2. Apple Reportedly Boosts Foldable Panel Orders to 20 Million, Suggesting Strong Demand for Foldable iPhone
  3. Smriti Irani Backs Women Entrepreneurs With SPARK Collective Push and British Council Partnership
  4. Oppo Watch X3 With Snapdragon W5 Chipset, Over 100 Sports Modes Launched
  5. Oppo Find N6 Launched With Snapdragon 8 Elite Gen 5 SoC, 6,000mAh Battery: Price, Features
  6. Poco X8 Pro Series Launched in India With Up to 9,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  7. OnePlus Pad 3 Tipped to Launch With 13.2-Inch Display, Snapdragon 8 Elite Gen 5 Chip
  8. Vivo X500 Series Chipsets Tipped Months Ahead of Launch; Vivo Pro Max Could Also Debut
  9. Argentina Bans Polymarket Over Unregulated Crypto Betting Concerns: Report
  10. Oura Ring 4 Launched in India With Smart Sensing Technology and HRV Tracking: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.