/?pid=researchers-find-unfixable-vulnerability-inside-intel-cpus-21586

Updated:04:54 PM EST Feb 27


this is ggmania.com subsite Researchers Find Unfixable Vulnerability Inside Intel CPUs - TechAmok

Researchers Find Unfixable Vulnerability Inside Intel CPUs - [security]
08:17 AM EST - Mar,06 2020 - post a comment

Researchers have found another vulnerability Inside Intel's Converged Security and Management Engine (CSME). For starters, the CSME is a tiny CPU within a CPU that has access to whole data throughput and is dedicated to the security of the whole SoC. The CSME system is a kind of a black box, given that Intel is protecting its documentation so it can stop its copying by other vendors, however, researchers have discovered a flaw in the design of CSME and are now able to exploit millions of systems based on Intel CPUs manufactured in the last five years. Discovered by Positive Technologies, the flaw is lying inside the Read-Only Memory (ROM) of the CSME. Given that the Mask ROM is hardcoded in the CPU, the exploit can not be fixed by a simple firmware update. The researchers from Positive Technologies describe it as such: "Unfortunately, no security system is perfect. Like all security architectures, Intel's had a weakness: the boot ROM, in this case. An early-stage vulnerability in ROM enables control over the reading of the Chipset Key and generation of all other encryption keys. One of these keys is for the Integrity Control Value Blob (ICVB). With this key, attackers can forge the code of any Intel CSME firmware module in a way that authenticity checks cannot detect. This is functionally equivalent to a breach of the private key for the Intel CSME firmware digital signature, but limited to a specific platform."

Every CPU manufactured in the last 5 years is subject to exploit, except the latest 10th generation, Ice Point-based chipsets and SoCs. The only solution for owners of prior generation CPUs is to upgrade to the latest platform as a simple firmware update can not resolve this. The good thing, however, is that to exploit a system, an attacker must have physical access to the hardware in question, as remote exploitation is not possible.

Short overview of recent news articles

Have RAM and GPU Prices Peaked? (Feb,27 2026 )

Zoom 'Update' Trap: Fake Site Infects 1,437 Users with Spyware in (Feb,27 2026 )

Stop WASTING Money on Fancy RAM (Feb,27 2026 )

Drunk AI robot (Feb,27 2026 )

AirSnitch Exposes Critical Flaw: Wi-Fi Client Isolation Broken in (Feb,26 2026 )

Revolutionary Ultrasonic Knife Hits Kitchens: C-200 Vibrates for (Feb,26 2026 )

Apple Scores Historic NATO Security Clearance: iPhone and iPad First (Feb,26 2026 )

Kali Linux Goes AI-Powered: Claude Now Runs Your Pen Tests in Plain (Feb,26 2026 )

Resident Evil Requiem - Stunning on PS5 Pro + PS5/Xbox Series X|S (Feb,26 2026 )

Samsung Galaxy S26 Ultra Flexes Hardware Muscle Over iPhone 17 Pro (Feb,26 2026 )

The Galaxy S26 Ultra has a 'wow' feature with video Lock (Feb,26 2026 )

I built the most BORING PC possible... and here is why it's (Feb,26 2026 )

Micron Blasts GDDR7 as Gaming Bottleneck While Nvidia's RTX 50 (Feb,26 2026 )

UK Tightens Grip on Streaming Giants: Age Verification Now Mandatory (Feb,26 2026 )

Samsung Previews New AI Features Ahead of Flagship Phone Launch (Feb,25 2026 )

China's DeepSeek Bars Nvidia and AMD from New AI Model, Boosts (Feb,25 2026 )

Avast Impersonation Scam: Fake Site Tricks Users into Handing Over (Feb,25 2026 )

Microsoft Pulls the Plug: Windows Server 2016 and 2016-Era Windows (Feb,25 2026 )

I Scrapped 13 MACHINES to Prove a Point: STOP BUYING These Brands! (Feb,25 2026 )

How Stealthy was the 7zip Malware and how to spot it? (Feb,25 2026 )

Microsoft Drops Fresh Non-Security Boost for Windows 11 24H2 and (Feb,25 2026 )

Game-Changer: ASML's 1kW EUV Upgrade Promises 50% Chip Production (Feb,24 2026 )

This Outstanding Cooling Technology Might Have No Future (Feb,24 2026 )

AMD Strix Halo 395 vs Intel Panther Lake - Real Benchmarks (Feb,24 2026 )

Anthropic published a blog post saying Claude can modernize COBOL (Feb,24 2026 )

WhatsApp Goes Beyond 2FA: Extra Password Layer Makes Accounts Nearly (Feb,24 2026 )

Google Chrome Gets February 23 Security Boost with 3 High Fixes (Feb,24 2026 )

Stargate Stalls: OpenAI's $500B Dream Hits Roadblocks as $14B 2026 (Feb,23 2026 )

Google Crushes Cyber Threats: Blocks 1.75 Million Bad Apps and Bans (Feb,23 2026 )

Bitcoin Miner Bitdeer Sells Everything: Treasury Hits Zero in AI (Feb,22 2026 )

HW News - More Valve RAM Shortages, Tariffs Ruling, AI Causes PS6 (Feb,22 2026 )

Microsoft's Deep Integration of Copilot in Windows 11 Raises (Feb,22 2026 )

Elon Musk Confirms X Money Now Live in Internal Beta for Employees, (Feb,22 2026 )

Scream (1996) Flashback Review (Feb,22 2026 )

PayPal Confirms Major Breach: SSNs, Emails, and More Exposed from (Feb,22 2026 )

Does Freezing Help Delidding? 9850X3D Delid & Overclocking Test (Feb,22 2026 )

Microsoft is phasing out the custom primary password feature in its (Feb,22 2026 )

Everyone is Buying the Wrong Dash Cam! (2026) (Feb,21 2026 )

Big Brother on Discord: Leaked Code Shows Age Verification Runs You (Feb,20 2026 )

OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened (Feb,19 2026 )

Google Adds Satellite SOS to its Affordable Pixel Phone (Feb,19 2026 )

Phison CEO Warns: AI-Driven NAND and DRAM Shortage Could Bankrupt (Feb,19 2026 )

NVIDIA CEO hypes up GTC 2026, promises to unveil a chip that will (Feb,19 2026 )

Microsoft is uploading your confidential emails to Copilot for (Feb,19 2026 )

Anthropic Releases Claude Sonnet 4.6 with Improved Coding, Computer (Feb,18 2026 )

Apple Eyeing A Partnership With Chinese Memory Makers YMTC And CXMT (Feb,17 2026 )

This $60,000 TV was IRRESISTIBLE (Feb,17 2026 )

Keenadu Android Backdoor Infects Firmware, Spreads via Google Play (Feb,17 2026 )

Discord's ID Check Nightmare Sparks Massive Exodus to TeamSpeak (Feb,17 2026 )

Amazing Robot Performance at the 2026 Spring Festival Gala (Feb,17 2026 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs