In a study titled βTEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition,β researchers from Georgia Tech and Purdue University have demonstrated that even the latest Intel and AMD server-grade Trusted Execution Environments (TEEs)βincluding Intelβs SGX, TDX, and AMDβs SEV-SNPβcan be compromised using low-cost hardware tools.
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysThe researchers write, βWe show that, contrary to popular belief, bus interposition attacks on DDR5 server memory can be constructed cheaply by hobbyists, using parts easily obtained on e-commerce websites.β
Their experiments revealed that confidential virtual machines running on 5th-generation Intel Xeon and AMD Zen 5 processors are vulnerable to physical side-channel attacks that can exfiltrate cryptographic material, including attestation keys, from fully trusted systems.
Unlike earlier generations of Intel SGX, which included Merkle-tree-based integrity and replay protection, server-grade TEEs now rely on deterministic AES-XTS memory encryptionβa trade-off made to support large confidential VMs and reduce latency.
This design change, the authors argue, weakens the overall protection model. βUnlike client-based SGX, server TEEs use deterministic AES-XTS for memory encryption, and do not offer Merkle tree-based integrity or replay protectionsβ¦ This degraded protection in turn comes with usability and performance benefits.β
By exploiting this determinism, the team managed to observe and manipulate DDR5 memory transactions using a custom-built interposer that cost less than $1,000 to assemble from secondhand components.
βWe build a low budget DDR5 interposition setup capable of observing DRAM bus transactions,β the paper states. βOur attack can be done in under $1000 by computer hobbyists using equipment readily available on the secondhand market.β
Using their custom DDR5 snooping device, the researchers were able to extract Intelβs Provisioning Certification Key (PCK)βthe root of trust used to authenticate Intel SGX and TDX systems. Once extracted, the PCK allowed them to forge fully valid attestation reports, effectively impersonating trusted hardware to remote services.
The paper notes: βWe breach TDXβs and SGXβs security guarantees by extracting a Provisioning Certification Key (PCK) from a Xeon server in a fully trusted statusβ¦ Using our PCK we breach BUILDERNETβs use of TDX, violating its confidentiality and integrity.β
This means a malicious operator could create fake attested environments that appear cryptographically genuine to cloud providers and partners.
The researchers also demonstrated successful attacks against AMDβs SEV-SNP technologyβdespite its Ciphertext Hiding featureβand against NVIDIA Confidential Computing environments tied to Intelβs TDX ecosystem.
Their attack on AMD systems enabled the extraction of signing keys from OpenSSLβs ECDSA implementation inside supposedly protected virtual machines. The authors emphasize that βour results impact nearly all server-based TEE implementations with commercially-available hardware at the time of writing.β
The study further illustrates how forged attestation chains could compromise real-world applications such as BuilderNet, Phala Networkβs DSTACK SDK, and SECRET Networkβall of which rely on TEEs to secure blockchain or AI operations.
By bypassing attestation, attackers could intercept confidential transactions, extract private cryptographic keys, or even host unprotected LLM workloads while falsely claiming NVIDIA Confidential GPU certification.
Following responsible disclosure guidelines, the authors notified Intel (April 2025), NVIDIA (June 2025), and AMD (August 2025) before publishing the paper. The vendors have acknowledged the findings and are βconsidering releasing statements simultaneously with the public release of this paper.β
Related Posts:
- Phoenix (CVE-2025-6202): A New Rowhammer Attack Bypasses DDR5 Protections
- Data Centers Alert: AMD Addresses SEV-SNP Vulnerabilities in EPYC Processors
- Linux Kernel 6.16 Released: Boosting Hardware Support, Filesystems, & Networking
- ECDSA Vulnerability in YubiKey: What You Need to Know
- Researchers Expose Critical Isolation Vulnerability in Intel Trust Domain Extensions (TDX)
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!