---
title: Protecting Against SWAPGS Attack with Bitdefender Hypervisor Introspection
description: Today, multiple industry software and hardware vendors have published security advisories for CVE-2019-1125 related to a newly discovered side-channel attack, dubbed SWAPGS Attack
image: https://businessinsights.bitdefender.com/hubfs/2018/January/pins-cpu-processor-macro-40848.jpeg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Andrei Florescu**](https://businessinsights.bitdefender.com/author/andrei-florescu) / Aug 06, 2019

# Protecting Against SWAPGS Attack with Bitdefender Hypervisor Introspection

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection&utm_medium=social&utm_source=facebook)

- Speculative execution-based attacks exploit CPU architecture flaws to allow attackers to leak sensitive information from privileged operating system kernel memory
- The **SWAPGS Attack** leverages a new speculative execution vulnerability discovered by Bitdefender security researchers
- The **SWAGS Attack** circumvents all existing side-channel attack mitigations and allows attackers to gain unprivileged access to kernel sensitive data
- Bitdefender Hypervisor Introspection technology mitigates the **SWAPGS Attack** on unpatched Windows systems running on Citrix Hypervisor or KVM hypervisor

Today, multiple industry software and hardware vendors have published security advisories for CVE-2019-1125 related to a newly discovered side-channel attack, dubbed SWAPGS Attack. The **SWAPGS Attack** was identified and reported by Bitdefender security researchers working on hypervisor introspection and anti-exploit technologies. This led to a coordinated disclosure process that has included several strategic industry partners.

**How SWAPGS Attack Bypasses All Known Mitigations**

The **SWAPGS Attack** is a novel side-channel attack that is abusing a poorly documented behavior of a system instruction named **SWAPGS** to leak sensitive kernel information whilst bypassing all known side-channel attack mitigations. Successful exploitation allows an unprivileged attacker to leak portions of the kernel memory space which are privileged, and thereby thought to be protected by Kernel Page-Table Isolation (KPTI).

This attack exposes sensitive information from the OS kernel by abusing speculative execution of **SWAPGS** instruction. An attacker can force arbitrary memory dereferences in kernel, which leaves traces within the data caches. These signals can be picked-up by the attacker to infer the value located at the given kernel address. Consequently, attackers can exploit this vulnerability to search values in kernel memory (check if a given value is located at a given kernel address) or leak values from arbitrary kernel addresses.

The primary advantage of this newly described technique is that it bypasses every known mitigation implemented so far.

An in-depth analysis is publicly available [in a technical whitepaper](https://businessresources.bitdefender.com/bypassing-kpti-speculative-behavior-swapgs-instruction?utm_campaign=swapgs&utm_source=web&hsLang=en-us) published by Bitdefender Labs. The paper fully documents the vulnerability, exploit, attack consequences, and available mitigations.

**Background Information on Speculative Execution and Side Channel Attacks**

In 2018, the security research community first reported a new class of cybersecurity vulnerabilities in modern CPUs. At the root, this class of vulnerabilities relies on a common feature of modern CPUs called ‘speculative execution’. Speculative execution allows the CPU to execute instructions before knowing whether the results of execution are required or not. This class of vulnerabilities can be exploited via side-channel attacks. Successful exploitation allows an unprivileged attacker to break the basic memory isolation provided by hardware to gain access to privileged data which would normally not be accessible.

The first vulnerabilities, dubbed [Meltdown](https://meltdownattack.com/) and [Spectre](https://spectreattack.com/), were reported by Google Project Zero security researchers as well as Graz University of Technology and other industry researchers. Since the first reports came out, research efforts focused on speculative-execution attacks have yielded a number of reported vulnerabilities: [Foreshadow](https://foreshadowattack.eu) (reported by Intel as [L1TF](https://www.intel.com/content/www/us/en/architecture-and-technology/l1tf.html)), [ZombieLoad](https://zombieloadattack.com), and the [Microarchitectural Data Sampling (MDS)](https://mdsattacks.com/) attacks.

Attack mitigations for this class of vulnerabilities fall into three broad categories:

- **Hardware.** These are fixes included directly within hardware and apply to only generations of CPUs which were built after the architectural flaws were identified.
- **Software.** These are patch implementations which function entirely within software. Kernel Page Table Isolation (KPTI) is an example of a fix that protects the kernel memory in an isolated virtual address space, thus rendering several speculative side-channel attacks, such as Meltdown, ineffective;
- **Microcode**. These mitigations require cooperation between hardware and software. The hardware vendor supplies a microcode patch to expose new functionality (for example, the Spectre, L1TF or MDS mitigations) which are then used by the hypervisor or the operating system vendor(s) to mitigate the vulnerabilities.

Currently, all the indicated side-channels are mitigated by at least one of these three broad categories. However, the **SWAPGS Attack** is capable of bypassing all known side-channel attack mitigations.

**SWAPGS Attack Prevention with Hypervisor Introspection**

Bitdefender Hypervisor Introspection (HVI) leverages CPU virtualization features (Intel VT-x, for example) to provide new levels of protection. HVI first analyses the memory of the guest Virtual Machine (VM) to identify objects of interest. By leveraging technologies such as the Extended Page Table (EPT), HVI protects objects of interest from unauthorized access. For example, code sections may be protected against writes, while data sections may be protected against instruction execution.

Bitdefender HVI mitigates **SWAPGS Attack**, providing organizations with a compensating control until patches from impacted vendors are applied. Bitdefender achieves this by instrumenting each vulnerable **SWAPGS** instruction to insure it will not execute speculatively. This denies attackers the opportunities to leak kernel memory on vulnerable, non-patched Windows kernels. At runtime, HVI analyzes the kernel memory space of protected VMs and identifies vulnerable gadgets. The vulnerable gadgets are then serialized and become non-exploitable. The performance impact of this mitigation is negligible.

Bitdefender HVI is currently available for Citrix Hypervisor and KVM hypervisor. The following video demonstrates the **SWAPGS Attack** prevention at work:

 

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/average-ddos-attack-volume-in-europe-tripled-in-a-year-new-data-reveals?hsLang=en-us>

### [Average DDoS Attack Volume Tripled in a Year, New Data Reveals](https://businessinsights.bitdefender.com/average-ddos-attack-volume-in-europe-tripled-in-a-year-new-data-reveals?hsLang=en-us)

<https://businessinsights.bitdefender.com/what-are-ransomware-families-and-why-knowing-them-can-help-your-business-avoid-attack?hsLang=en-us>

### [What Are Ransomware Families? (And Why Knowing Them Can Help Your Business Avoid Attack)](https://businessinsights.bitdefender.com/what-are-ransomware-families-and-why-knowing-them-can-help-your-business-avoid-attack?hsLang=en-us)

<https://businessinsights.bitdefender.com/bec-attacks-in-2023-what-organizations-need-to-know?hsLang=en-us>

### [BEC Attacks in 2023: What Organizations Need to Know](https://businessinsights.bitdefender.com/bec-attacks-in-2023-what-organizations-need-to-know?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andrei Florescu",
    "url" : "https://businessinsights.bitdefender.com/author/andrei-florescu"
  },
  "dateModified" : "2019-08-06T23:24:35.459Z",
  "datePublished" : "2019-08-06T23:06:41.000Z",
  "headline" : "Protecting Against SWAPGS Attack with Bitdefender Hypervisor Introspection",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/2018/January/pins-cpu-processor-macro-40848.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/protecting-against-swapgs-attack-with-bitdefender-hypervisor-introspection",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```