/?pid=researchers-find-unfixable-vulnerability-inside-intel-cpus-21586

Updated:11:18 AM EST Jan 09


this is ggmania.com subsite Researchers Find Unfixable Vulnerability Inside Intel CPUs - TechAmok

Researchers Find Unfixable Vulnerability Inside Intel CPUs - [security]
08:17 AM EST - Mar,06 2020 - post a comment

Researchers have found another vulnerability Inside Intel's Converged Security and Management Engine (CSME). For starters, the CSME is a tiny CPU within a CPU that has access to whole data throughput and is dedicated to the security of the whole SoC. The CSME system is a kind of a black box, given that Intel is protecting its documentation so it can stop its copying by other vendors, however, researchers have discovered a flaw in the design of CSME and are now able to exploit millions of systems based on Intel CPUs manufactured in the last five years. Discovered by Positive Technologies, the flaw is lying inside the Read-Only Memory (ROM) of the CSME. Given that the Mask ROM is hardcoded in the CPU, the exploit can not be fixed by a simple firmware update. The researchers from Positive Technologies describe it as such: "Unfortunately, no security system is perfect. Like all security architectures, Intel's had a weakness: the boot ROM, in this case. An early-stage vulnerability in ROM enables control over the reading of the Chipset Key and generation of all other encryption keys. One of these keys is for the Integrity Control Value Blob (ICVB). With this key, attackers can forge the code of any Intel CSME firmware module in a way that authenticity checks cannot detect. This is functionally equivalent to a breach of the private key for the Intel CSME firmware digital signature, but limited to a specific platform."

Every CPU manufactured in the last 5 years is subject to exploit, except the latest 10th generation, Ice Point-based chipsets and SoCs. The only solution for owners of prior generation CPUs is to upgrade to the latest platform as a simple firmware update can not resolve this. The good thing, however, is that to exploit a system, an attacker must have physical access to the hardware in question, as remote exploitation is not possible.

Short overview of recent news articles

GOOD LUCK, HAVE FUN, DON'T DIE Trailer 2 (2026) Sam Rockwell (Jan,09 2026 )

NVIDIA Releases GeForce 591.74 WHQL Drivers with DLSS 4.5 Support (Jan,07 2026 )

Predator: Badlands Exclusive Deleted Scene (2025) (Jan,07 2026 )

Greenland 2: Migration - Official Trailer 3 (2026) Gerard Butler, (Jan,06 2026 )

The Best Laptops of 2025 - For Gaming, Creators & Students! (Jan,05 2026 )

Punkt Updates its Privacy-Focused Smartphone (Jan,05 2026 )

Clicks Launches New Ways to Add a Physical Keyboard to Your Life (Jan,05 2026 )

Building a PC for the First Time (Jan,05 2026 )

Building a PC in 2026 (Jan,03 2026 )

I want this phone so bad... - Samsung Galaxy Z TriFold (Jan,02 2026 )

The Real Finewine Strikes Again: Ryzen 5600X, 5700X & 5800XT Revisit (Jan,02 2026 )

Nokia N8 Symbian Re-Awakened With Passion (Jan,02 2026 )

Europe Forces Apple to Open up More of iOS (Jan,02 2026 )

Must have Privacy and Security Tweaks: 2026 Edition (Jan,02 2026 )

How Did RAM Get So Expensive?! (Jan,01 2026 )

GeForce RTX 5090 prices to soar to $5,000 as NVIDIA and AMD prep GPU (Dec,31 2025 )

Hacker arrested for KMSAuto malware campaign with 2.8 million (Dec,30 2025 )

Killer Whale - Official Trailer (2026) Virginia Gardner, Mel (Dec,29 2025 )

NVIDIA Showed Me Their Supercomputer (Dec,28 2025 )

2026 CPU Launches! AMD, Intel & NVIDIA: Buy Now or Wait? (Dec,28 2025 )

Disable this Windows Feature that Secretly Eats Up RAM! (Dec,27 2025 )

New Windows 11 vs Old Malware: Will it survive? (Dec,27 2025 )

Samsung TriFold Durability Test: We found the limit (Dec,27 2025 )

TRUST WALLET CONFIRMS SECURITY BREACH (Dec,26 2025 )

Xiaomi 17 Ultra Leads And Samsung To Follow With A 10 Percent Price (Dec,26 2025 )

Merry Christmas Gaming Insanity (Dec,25 2025 )

Battlefield 6 - Official PS5 Features Trailer (Dec,24 2025 )

NVIDIA GeForce Hotfix Driver 591.67 Released (Dec,24 2025 )

Finally! A Battery That's Better Than Energizer and Duracell! (Dec,23 2025 )

NVIDIA Killing Cheap 16GB Local AI GPUs? (Dec,22 2025 )

Top 10 Movie Sequels of All Time (Dec,21 2025 )

He Built a Privacy Tool. Now He's Going to Prison (Kone Rodriguez, (Dec,21 2025 )

Insane Moves! B-Boy Shigekix vs. B-Boy Issin - Red Bull BC One World (Dec,20 2025 )

9800X3D & RTX 5070 Ti Gaming PC - MSI Project Zero Done Right (Dec,20 2025 )

The XG27AQWMG Sets a New Standard for 1440p OLED (Dec,19 2025 )

OnePlus 15R Boasts Huge 7,400 mAh Battery (Dec,19 2025 )

Motorola Refreshes moto g power for 2026 (Dec,19 2025 )

NVIDIA GeForce 591.59 WHQL Driver (Dec,18 2025 )

Are We Quitting YouTube Due To DRAM Apocalypse? (Dec,18 2025 )

The Samsung TriFold is AWESOME! (Dec,16 2025 )

$30 vs $30,000 TV (Dec,16 2025 )

Stranger Things 5 - Volume 2 Trailer (Dec,16 2025 )

Google Brings Live Video Sharing to 911 Calls on Android (Dec,14 2025 )

Samsung One UI 8.5 Will Offer New Features (Dec,14 2025 )

Dell AW3225QF Review - 32-inch curved gaming monitor (Dec,14 2025 )

HW News - AMD Says AI Definitely, Absolutely Not A Bubble, New (Dec,13 2025 )

The BEST Smartphones of 2025! (Dec,13 2025 )

10 Atmospheric Games That Might CHANGE YOUR LIFE (Dec,11 2025 )

Samsung Galaxy S26 Ultra - Samsung Isn't Hiding It Anymore (Dec,11 2025 )

AMD Releases Adrenalin Edition 25.12.1 WHQL Drivers (Dec,10 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs