TDXploit: Novel Techniques for Single-Stepping and Cache Attacks on Intel TDX

Fabian Rauscher, Luca Wilke, Hannes Weissteiner, Thomas Eisenbarth, Daniel Gruss

34th USENIX Security Symposium · Day 1

Intel Trust Domain Extensions (**TDX**) represent the second generation of Trusted Execution Environments (TEEs), designed to protect entire virtual machines (VMs), known as trust domains (TDs), from a potentially malicious host system. While TDX aims to provide robust memory and state isolation, the shared underlying hardware often introduces side channels, posing a significant security challenge. This paper, "TDXploit: Novel Techniques for Single-Stepping and Cache Attacks on Intel TDX," authored by Fabian Rauscher, Luca Wilke, Hannes Weissteiner, Thomas Eisenbarth, and Daniel Gruss, unveils critical vulnerabilities in Intel's latest TDX implementations, specifically addressing its single-stepping mitigations and memory access defenses.

AI review

This is exactly the kind of research that justifies the existence of security conferences. They didn't just find one bug — they systematically dismantled Intel's latest TDX defenses, turned the mitigation into the attack primitive, and discovered that clflush ignores HKIDs on 5th gen Xeons. The LFSR recovery is elegant, the Flush+Flush on private memory is devastating, and the end-to-end attacks prove it all works.