/?pid=researchers-find-unfixable-vulnerability-inside-intel-cpus-21586

Updated:11:20 AM EDT Apr 23


this is ggmania.com subsite Researchers Find Unfixable Vulnerability Inside Intel CPUs - TechAmok

Researchers Find Unfixable Vulnerability Inside Intel CPUs - [security]
08:17 AM EST - Mar,06 2020 - post a comment

Researchers have found another vulnerability Inside Intel's Converged Security and Management Engine (CSME). For starters, the CSME is a tiny CPU within a CPU that has access to whole data throughput and is dedicated to the security of the whole SoC. The CSME system is a kind of a black box, given that Intel is protecting its documentation so it can stop its copying by other vendors, however, researchers have discovered a flaw in the design of CSME and are now able to exploit millions of systems based on Intel CPUs manufactured in the last five years. Discovered by Positive Technologies, the flaw is lying inside the Read-Only Memory (ROM) of the CSME. Given that the Mask ROM is hardcoded in the CPU, the exploit can not be fixed by a simple firmware update. The researchers from Positive Technologies describe it as such: "Unfortunately, no security system is perfect. Like all security architectures, Intel's had a weakness: the boot ROM, in this case. An early-stage vulnerability in ROM enables control over the reading of the Chipset Key and generation of all other encryption keys. One of these keys is for the Integrity Control Value Blob (ICVB). With this key, attackers can forge the code of any Intel CSME firmware module in a way that authenticity checks cannot detect. This is functionally equivalent to a breach of the private key for the Intel CSME firmware digital signature, but limited to a specific platform."

Every CPU manufactured in the last 5 years is subject to exploit, except the latest 10th generation, Ice Point-based chipsets and SoCs. The only solution for owners of prior generation CPUs is to upgrade to the latest platform as a simple firmware update can not resolve this. The good thing, however, is that to exploit a system, an attacker must have physical access to the hardware in question, as remote exploitation is not possible.

Short overview of recent news articles

ATLAS | Official Trailer | Netflix (Apr,23 2024 )

The World's Fastest CPU (Technically...) - Intel i9-14900KS (Apr,22 2024 )

We can do THIS now! - Lumafield CT Scanner (Apr,22 2024 )

Huawei Pura 70 Ultra - Apple Should be WORRIED (Apr,21 2024 )

Sony 2024 TV Lineup Revealed (Apr,21 2024 )

ICE - A Thousand Suns / Episode 1 (Apr,20 2024 )

Minisforum V3 AMD Tablet Review (Apr,20 2024 )

AMD & Intel SLASH CPU Prices! (Apr,20 2024 )

EK is Imploding: Not Paying Employees, Partners, & Suppliers (Apr,20 2024 )

Backing Up My NAS To My... Parents' House? (Apr,20 2024 )

NEW Ryzen APU BEATS RTX 40 GPUs! (Apr,20 2024 )

(Live) Black Tape Project - All New Raw and Uncut - LA Fashion Week (Apr,20 2024 )

NVIDIA Geforce 552.22 WHQL Driver (Apr,19 2024 )

You Deserve this much OLED - AORUS CO49DQ (Apr,19 2024 )

Unreal Engine 5.4 looks ULTRA PHOTOREALISTIC (Apr,19 2024 )

Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit (Apr,18 2024 )

I Will Build You a PC Right Now! (Apr,18 2024 )

These games carry REAL security risks! BEWARE! (Apr,17 2024 )

Visible First to Offer Annual Payment Plan, with Discount up to 26% (Apr,17 2024 )

Is Coding Still Worth Learning in 2024? (Apr,17 2024 )

All New Atlas - Boston Dynamics (Apr,17 2024 )

The NEW Chip Inside Your Phone! (NPUs) (Apr,16 2024 )

XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel! (Apr,16 2024 )

The Most 2024 Laptop - Razer Blade 14 Review (Apr,15 2024 )

NEVER install these programs on your PC... EVER!!! (Apr,15 2024 )

Use Live Translate on Galaxy S24 series to translate a call's (Apr,14 2024 )

I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam? (Apr,14 2024 )

Samsung Galaxy Ring - This Just Got Interesting (Apr,13 2024 )

Piracy Is Over Party - WAN Show April 12, 2024 (Apr,13 2024 )

Conan O'Brien Needs a Doctor While Eating Spicy Wings (Apr,13 2024 )

Beatbox Jcob recreats every sound (Apr,13 2024 )

Intel is Gunning for NVIDIA (Apr,13 2024 )

Building a Budget DIY Home Surveillance System (Apr,13 2024 )

Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop (Apr,12 2024 )

DARK MATTER Trailer (2024) New Sci-Fi Movies 4K (Apr,11 2024 )

How to Build a PC, the last guide you'll ever need! (2024 Update) (Apr,11 2024 )

Intel 300 CPU Review - The Pentium Replacement is Finally Here... (Apr,10 2024 )

Wubuntu, the Dubious Linux Windows (Apr,10 2024 )

A Lite Version Of Windows 11 To Be Released This Year (Apr,09 2024 )

This $150 Smartphone might be All You Need (Apr,09 2024 )

I Can't Believe These are Real - Reacting to Ridiculous PCs on (Apr,09 2024 )

A new video shows AirPower prototype charging an Apple Watch (Apr,08 2024 )

Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved (Apr,08 2024 )

20 COOL GADGETS YOU SHOULD SEE (Apr,08 2024 )

New HTTP/2 vulnerability leaves servers in danger of devastating DoS (Apr,08 2024 )

3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance? (Apr,07 2024 )

The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024 (Apr,06 2024 )

Top NEW RELEASES on Netflix in APRIL 2024 (Apr,06 2024 )

Magician vs Slow-Mo Camera (Skill Challenge) (Apr,05 2024 )

Re-Ranking All Current GPUs From Worst to Best (2024 Update) (Apr,05 2024 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs