Jasper Lake EDS Vol1
User Mode Instruction Prevention (UMIP)
User Mode Instruction Prevention (UMIP) provides additional hardening capability to OS kernel by allowing certain instructions to execute only in supervisor mode (Ring 0).
If the OS opt-in to use UMIP, the following instruction are enforced to run in supervisor mode:
- SGDT - Store the GDTR register value
- SIDT - Store the IDTR register value
- SLDT - Store the LDTR register value
- SMSW - Store Machine Status Word
- STR - Store the TR register value
An attempt at such execution in user mode causes general protection exception (#GP).
UMIP specifications and functional descriptions are included in the Intel® 64 Architectures Software Developer’s Manual, Volume 3, available at: