Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation
Tristan Hornetz, Lukas Gerlach, Michael Schwarz
Abstract
Transient-execution attacks such as Meltdown, Foreshadow, and MDS expose fundamental flaws in modern CPUs, yet reproducing and comparing them today is increasingly complex: vulnerable CPUs are scarce, lab setups cannot be shared easily, and results are hard to compare. These challenges make it difficult to evaluate detection tools, study exploits, or integrate attacks into teaching environments. As vulnerable CPUs become rarer, hands-on experimentation and consistent benchmarking gradually become infeasible, complicating both research and education in microarchitectural security.
In this paper, we introduce Crucible, a software-only framework that transparently simulates Meltdown-type transient execution vulnerabilities on any x86 CPU. Crucible simulates transient execution after a fault by shadowing the instruction stream in a different process to emulate key microarchitectural effects, such as cache leakage, transient windows, and fence behavior. Crucible runs unmodified public proofs-ofconcept and even complete exploits with leakage patterns that match real hardware. We reproduce 3 full end-to-end exploits for well-known vulnerabilities, such as key extraction from VeraCrypt with Meltdown, on unaffected hardware. Crucible supports testing of binary-only applications and integrates with state-of-the-art fuzzers, which detect simulated vulnerabilities with results comparable to real CPUs. We further simulate two artificial vulnerabilities to evaluate generalization in fuzzer behavior. Our work enables systematic, repeatable experiments, preserves legacy vulnerabilities for future use, allows comparison of vulnerability detection approaches, and provides an accessible platform for teaching and training in CPU security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 943b768b-e5d4-4c2c-9678-3ade62acc387Builds on32
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
Related papers
- Speculation at Fault: Modeling and Testing Microarchitectural Leakage of CPU ExceptionsJana Hofmann, Emanuele Vannacci, Cédric Fournet, Boris Köpf et al.USENIX Security 2023
- Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution VulnerabilitiesDaniel Weber, Fabian Thomas, Leon Trampert, Ruiyi Zhang et al.S&P 2026 · 1 citation
- SpecDoctor: Differential Fuzz Testing to Find Transient Execution VulnerabilitiesJaewon Hur, Suhwan Song, Sunwoo Kim, Byoungyoung LeeCCS 2022 · 19 citations
- Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel ProcessorsAnirban Chakraborty, Nimish Mishra, Debdeep MukhopadhyayUSENIX Security 2024 · 3 citations
- Medusa: Microarchitectural Data Leakage via Automated Attack SynthesisDaniel Moghimi, Moritz Lipp, Berk Sunar, Michael SchwarzUSENIX Security 2020
