/?pid=researchers-find-unfixable-vulnerability-inside-intel-cpus-21586

Updated:06:27 PM EDT Sep 15


this is ggmania.com subsite Researchers Find Unfixable Vulnerability Inside Intel CPUs - TechAmok

Researchers Find Unfixable Vulnerability Inside Intel CPUs - [security]
08:17 AM EST - Mar,06 2020 - post a comment

Researchers have found another vulnerability Inside Intel's Converged Security and Management Engine (CSME). For starters, the CSME is a tiny CPU within a CPU that has access to whole data throughput and is dedicated to the security of the whole SoC. The CSME system is a kind of a black box, given that Intel is protecting its documentation so it can stop its copying by other vendors, however, researchers have discovered a flaw in the design of CSME and are now able to exploit millions of systems based on Intel CPUs manufactured in the last five years. Discovered by Positive Technologies, the flaw is lying inside the Read-Only Memory (ROM) of the CSME. Given that the Mask ROM is hardcoded in the CPU, the exploit can not be fixed by a simple firmware update. The researchers from Positive Technologies describe it as such: "Unfortunately, no security system is perfect. Like all security architectures, Intel's had a weakness: the boot ROM, in this case. An early-stage vulnerability in ROM enables control over the reading of the Chipset Key and generation of all other encryption keys. One of these keys is for the Integrity Control Value Blob (ICVB). With this key, attackers can forge the code of any Intel CSME firmware module in a way that authenticity checks cannot detect. This is functionally equivalent to a breach of the private key for the Intel CSME firmware digital signature, but limited to a specific platform."

Every CPU manufactured in the last 5 years is subject to exploit, except the latest 10th generation, Ice Point-based chipsets and SoCs. The only solution for owners of prior generation CPUs is to upgrade to the latest platform as a simple firmware update can not resolve this. The good thing, however, is that to exploit a system, an attacker must have physical access to the hardware in question, as remote exploitation is not possible.

Short overview of recent news articles

Microsoft warns Office 2016/2019 users to switch to the cloud as (Sep,15 2025 )

Get Windows 11 25H2 Right Now (Sep,15 2025 )

iPhone 17 Pro VS iPhone 16 Pro VS iPhone 15 Pro VS iPhone 14 Pro (Sep,14 2025 )

What's the AMD Alternative to an RTX 5070? (Sep,11 2025 )

Apple got my wife, they might get me next... (Sep,10 2025 )

Which Phone Has The Fastest Wi-Fi 7? (Sep,09 2025 )

Apple Event - September 9 (Sep,09 2025 )

Ferrari F430 *MANUAL* with TUBI EXHAUST SCREAMING on the AUTOBAHN! (Sep,08 2025 )

AMD Adrenalin 25.9.1 Driver (Sep,08 2025 )

Google Brings AI Text Tools to its Keyboard (Sep,08 2025 )

The Fastest Lap In F1 History: Max Verstappen's Pole Lap | 2025 (Sep,06 2025 )

You can't download and install Windows 11 25H2 yet as Microsoft (Sep,06 2025 )

A House of Dynamite - Official Teaser (2025) Rebecca Ferguson, Greta (Sep,04 2025 )

RTX 5060 Ti 16GB + Ryzen 5 5600 : Test in 17 Games (Sep,04 2025 )

BUGONIA Trailer 2 (2025) Emma Stone, Jesse Plemons (Sep,02 2025 )

Huawei unveils world-leading AI supercharged hard drive to power (Sep,02 2025 )

AM4 Lives: AMD Ryzen 5 5500X3D CPU Review & Benchmarks (Sep,01 2025 )

I was wrong, iPhone IS better than Android...- 30 Day iPhone (Aug,29 2025 )

303KM/H BMW X5 M50i GPOWER SOUNDS LIKE THUNDER (Aug,29 2025 )

NVIDIA GeForce 581.15 WHQL drivers (Aug,29 2025 )

Apple Intelligence vs Galaxy AI / Google Pixel AI / Xiaomi HyperAI - (Aug,28 2025 )

The Woman in Cabin 10 - Official Trailer (Aug,28 2025 )

YANGWANG U9 Breaks Global EV Top Speed Record (Aug,28 2025 )

AMD B850 Motherboard Roundup: Sub $200 Models (Aug,26 2025 )

Gamers Nexus: Our Channel Could Be Deleted (Aug,25 2025 )

2025 Audi A5 E-Hybrid 299HP "250KMH is back!!" // REVIEW on (Aug,24 2025 )

I Can't Stop You From Buying This... But I'll Try - GeForce RTX (Aug,23 2025 )

NVIDIA GeForce 581.08 WHQL Driver (Aug,23 2025 )

Murcielago with flames chasing an F1 car on highway (2025) (Aug,21 2025 )

Windows 11 24H2 Security Update Causes SSD/HDD Failures and (Aug,18 2025 )

Samsung Galaxy Z Fold 7 - Tips, Tricks & Hidden Features! (Aug,17 2025 )

500Hz OLEDs are Awesome - Gigabyte AORUS FO27Q5P Review (Aug,17 2025 )

They Said my Gaming & Badminton Club Would Never OPEN! (Aug,17 2025 )

NVIDIA GeForce Game Ready 580.97 WHQL Driver (Aug,13 2025 )

When your Bro needs a new computer... (Aug,13 2025 )

WhatsApp's latest update is a huge "convenience" for group chats (Aug,12 2025 )

COLLAPSE: Intel is Falling Apart (Aug,12 2025 )

Useless or Genius: NVMe SSD Coolers (Aug,11 2025 )

2025 NEW! Audi A6 3.0 TFSI - BETTER than BMW 5? / (Aug,11 2025 )

Ryzen 7 5800X3D vs. 9800X3D, Battlefield 6 Open Beta Benchmark (Aug,10 2025 )

How to Enter BIOS from Windows Using CMD | Easiest Method (No Key (Aug,10 2025 )

Battlefield 6 Open Beta Benchmark: 9800X3D vs. 9700X vs. 265K (Aug,09 2025 )

WhatsApp finally adds a useful photo feature for Android users (Aug,09 2025 )

OpenAI announces ChatGPT changes following user feedback (Aug,09 2025 )

Corsair MAKR75 Review - Ultimate DIY Keyboard Kit (Aug,06 2025 )

1176 Hardware vs Plugin - Is There Really a Difference? (Aug,06 2025 )

Do this NOW: Use Disposable Windows for Maximum Security! (Aug,06 2025 )

CPU/GPU Scaling: Ryzen 7 5800X3D (RTX 5090, 5080, RX 9070 & 9060 XT) (Aug,06 2025 )

XRP To $1000 By 2030... Know What You Hold BUT SELL YOUR XRP HERE: ? (Aug,05 2025 )

NURBURGRING HEAVY RAINSTORM! MANY Fails, Spins & Slippery Action! (Aug,03 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs