Supporting Rowhammer research to protect the DRAM ecosystem
Google and researchers from ETH Zurich have demonstrated new Rowhammer attacks ("Phoenix") that successfully bypass enhanced Target Row Refresh (TRR) mitigations on production DDR5 memory, achieving the first privilege escalation exploit on standard desktop systems with DDR5. The research reveals that current probabilistic defenses like TRR and ECC are insufficient against sophisticated attackers who understand specific memory subsystem architectures, highlighting the need for stronger mitigations like the PRAC standard in upcoming DDR5/LPDDR6 versions.
Summary
Google and researchers from ETH Zurich have demonstrated new Rowhammer attacks ("Phoenix") that successfully bypass enhanced Target Row Refresh (TRR) mitigations on production DDR5 memory, achieving the first privilege escalation exploit on standard desktop systems with DDR5. The research reveals that current probabilistic defenses like TRR and ECC are insufficient against sophisticated attackers who understand specific memory subsystem architectures, highlighting the need for stronger mitigations like the PRAC standard in upcoming DDR5/LPDDR6 versions.
Indicators of Compromise
- malware — Phoenix
- mitre_attack — T1548 - Abuse Elevation Control Mechanism
- mitre_attack — T1561 - Disk Wipe