In reply to @v12sec

V12

V12

@v12sec · Twitter ·

We craft the replacement, overwriting a function pointer and its argument to enter Open Enclave's register restore path with a host-crafted register context. This yields full control over enclave registers and allows code execution within the trusted context. Our POC makes the pwned enclave memcpy its secrets out to host memory. This again allows the server to impersonate the enclave, decrypting all incoming contact information.