Don't panic about the new 'Prime' Meltdown and Spectre CPU exploits

Existing software patches offer protection, but future hardware fixes may not.

Credit: Google/Natascha Eibl

The news sounds bad at first blush: Researchers from Nvidia and Princeton University have discovered fresh ways to exploit the Meltdown and Spectre CPU vulnerabilities present in every modern computer processor. But while the new MeltdownPrime and SpectrePrime attacks prove that the initial exploits aren’t necessarily the only way to trigger the vulnerabilities lurking inside chips, everyday computer users shouldn’t freak out about them.

The new vulnerabilities pit the multiple CPU cores inside modern processors against each other and take advantage of the way memory cache access works in multi-core systems. The Register’s synopsis and the research paper have more in-depth technical details if you want them. Like Meltdown and Spectre, a successful attack can extract sensitive information, including passwords.

Now for the good news: The researchers didn’t release exploit code for MeltdownPrime and SpectrePrime. Better yet, the patches already planned for Meltdown and Spectre should protect against these new variants, too. All major operating systems released Meltdown protections as soon as the exploits were announced, Intel is starting to roll out CPU firmware updates after a disastrous first attempt, and industry leaders are tweaking compilers and how code is handled to harden other software against Spectre.

Core i7-8700K Coffee Lake Gordon Mah Ung

A variety of recent Intel processors.

Safeguarding against Meltdown, Spectre, and these new Prime variants isn’t straightforward though, as the processor flaws touch every aspect of your PC. PCWorld’s tutorial on how to protect your PC against Meltdown and Spectre can walk you through the complicated patching process. Researchers are starting to see malware probing the vulnerabilities in the wild, so you’ll also want to take additional steps to keep your data safe. Invest in solid data backup and Windows antivirus solutions if you haven’t already—they’re must-haves in today’s computing world.  

MeltdownPrime and SpectrePrime might complicate tomorrow’s computing world, though. Intel and AMD are building hardware fixes for the original CPU vulnerabilities into their next generations of processors, but these fresh attacks won’t get stopped by those, the researchers say.

“We believe that microarchitectural mitigation of our Prime variants will require new considerations. Where Meltdown and Spectre arise by polluting the cache during speculation, MeltdownPrime and SpectrePrime are caused by write requests being sent out speculatively in a system that uses an invalidation-based coherence protocol.”

Coincidentally, Intel expanded its bug bounty program yesterday, introducing a special program for “side-channel” attacks like these that pay up to $250,000 for disclosure of new exploits.

Stay patched, friends—but don’t panic.

Join the newsletter!

Or
Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Brad Chacos

PC World (US online)
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?