/?pid=21586

Updated:03:56 PM EST Dec 19


this is ggmania.com subsite Researchers Find Unfixable Vulnerability Inside Intel CPUs - TechAmok

Researchers Find Unfixable Vulnerability Inside Intel CPUs - [security]
08:17 AM EST - Mar,06 2020 - post a comment

Researchers have found another vulnerability Inside Intel's Converged Security and Management Engine (CSME). For starters, the CSME is a tiny CPU within a CPU that has access to whole data throughput and is dedicated to the security of the whole SoC. The CSME system is a kind of a black box, given that Intel is protecting its documentation so it can stop its copying by other vendors, however, researchers have discovered a flaw in the design of CSME and are now able to exploit millions of systems based on Intel CPUs manufactured in the last five years. Discovered by Positive Technologies, the flaw is lying inside the Read-Only Memory (ROM) of the CSME. Given that the Mask ROM is hardcoded in the CPU, the exploit can not be fixed by a simple firmware update. The researchers from Positive Technologies describe it as such: "Unfortunately, no security system is perfect. Like all security architectures, Intel's had a weakness: the boot ROM, in this case. An early-stage vulnerability in ROM enables control over the reading of the Chipset Key and generation of all other encryption keys. One of these keys is for the Integrity Control Value Blob (ICVB). With this key, attackers can forge the code of any Intel CSME firmware module in a way that authenticity checks cannot detect. This is functionally equivalent to a breach of the private key for the Intel CSME firmware digital signature, but limited to a specific platform."

Every CPU manufactured in the last 5 years is subject to exploit, except the latest 10th generation, Ice Point-based chipsets and SoCs. The only solution for owners of prior generation CPUs is to upgrade to the latest platform as a simple firmware update can not resolve this. The good thing, however, is that to exploit a system, an attacker must have physical access to the hardware in question, as remote exploitation is not possible.


Add your comment (free registrationrequired)

Short overview of recent news articles

Dec,19 2025 The XG27AQWMG Sets a New Standard for 1440p OLED
Dec,19 2025 OnePlus 15R Boasts Huge 7,400 mAh Battery
Dec,19 2025 Motorola Refreshes moto g power for 2026
Dec,18 2025 NVIDIA GeForce 591.59 WHQL Driver
Dec,18 2025 Are We Quitting YouTube Due To DRAM Apocalypse?
Dec,16 2025 The Samsung TriFold is AWESOME!
Dec,16 2025 $30 vs $30,000 TV
Dec,16 2025 Stranger Things 5 - Volume 2 Trailer
Dec,14 2025 Google Brings Live Video Sharing to 911 Calls on Android
Dec,14 2025 Samsung One UI 8.5 Will Offer New Features
Dec,14 2025 Dell AW3225QF Review - 32-inch curved gaming monitor
Dec,13 2025 HW News - AMD Says AI Definitely, Absolutely Not A Bubble, New
Dec,13 2025 The BEST Smartphones of 2025!
Dec,11 2025 10 Atmospheric Games That Might CHANGE YOUR LIFE
Dec,11 2025 Samsung Galaxy S26 Ultra - Samsung Isn't Hiding It Anymore
Dec,10 2025 AMD Releases Adrenalin Edition 25.12.1 WHQL Drivers
Dec,10 2025 S25 Ultra VS 17 Pro Max
Dec,09 2025 All You Need Is Kill - Official Trailer
Dec,09 2025 Why can’t you be NORMAL?!? Roasting Staff Setups
Dec,09 2025 A Ryzen Cooling MONSTER - be quiet Silent Loop 3 Review
Dec,07 2025 The Boys - Official Final Season Trailer
Dec,06 2025 Unemployed in your 30's
Dec,05 2025 Play Store Customers to Receive Automatic Payments from $700 Million
Dec,05 2025 Google's Second Release of Android 16 Brings Smart Notifications
Dec,05 2025 Netflix To Buy Warner Bros for $82.7 Billion
Dec,03 2025 Micron to Exit Crucial Consumer Business, Ending Retail SSD and DRAM
Dec,02 2025 Samsung Galaxy Z TriFold Unboxing!
Nov,30 2025 Top 5 Best CPUs of 2025
Nov,30 2025 Google Adding AirDrop to Android
Nov,29 2025 20 TOP ALIEXPRESS products for BLACK FRIDAY
Nov,26 2025 Stop Wasting Money on Premium Monitors
Nov,23 2025 The Blackest Friday - Tech News Nov 23
Nov,23 2025 T-Roc: Will this new VW be the best car of 2026?
Nov,23 2025 Can I build my own Steam Machine?
Nov,22 2025 50 NEXT-LEVEL Gadgets Every Man NEEDS to See
Nov,22 2025 RETURN TO SILENT HILL Trailer (2026)
Nov,20 2025 I was WRONG about the Porsche 911 GT3 (or was I?)
Nov,20 2025 Pi GPT Tool Turns Raspberry Pi into a ChatGPT-Powered Smart Device
Nov,17 2025 Rainbow Six Siege X - Official 'Team Rainbow's Last Mission'
Nov,17 2025 Stranger Things Seasons 1-4 Recap
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs