News

Another Intel Vulnerability, and it’s Unfixable…

Honestly, I saw this story this morning and I couldn’t help but think “what? Again… meh, same s*** different day” but that doesn’t make it any less of a serious issue. Researchers at Positive Technologies found the vulnerability Inside Intel’s Converged Security and Management Engine (CSME). I mean, that’s what I go digging through in my spare time too, but alas, they found that the CSME is actually a tiny CPU within a CPU.

The little chip in a chip is responsible for the security of the SoC. It’s basically a secure box for all the secret data handling on the chip I guess. However, they’ve cracked it and that means that now many millions of Intel CPU based systems from the last five years are now vulnerable.

Whoops

“Unfortunately, no security system is perfect. Like all security architectures, Intel’s had a weakness: the boot ROM, in this case. An early-stage vulnerability in ROM enables control over the reading of the Chipset Key and generation of all other encryption keys. One of these keys is for the Integrity Control Value Blob (ICVB). With this key, attackers can forge the code of any Intel CSME firmware module in a way that authenticity checks cannot detect. This is functionally equivalent to a breach of the private key for the Intel CSME firmware digital signature, but limited to a specific platform.” – Positive Technologies

Am I Safe?

It looks like every Intel CPU of the last 5 years is suffering this unfixable issue. However, the 10th Gen, Ice Point chipsets and SoCs are not affected by it. The only saving grace is that you need physical access to the hardware as it cannot be done remotely. Of course, that may be good for your gaming PC in your bedroom, not so great for your office computer in a sensitive industry.

Peter Donnell

As a child still in my 30's (but not for long), I spend my day combining my love of music and movies with a life-long passion for gaming, from arcade classics and retro consoles to the latest high-end PC and console games. So it's no wonder I write about tech and test the latest hardware while I enjoy my hobbies!

Disqus Comments Loading...

Recent Posts

Corsair Vengeance LPX Black 64GB (2x32GB) 3600MHz DDR4 Dual Channel Memory Kit

VENGEANCE LPX memory is designed for high-performance overclocking. The heatspreader is made of pure aluminium…

3 hours ago

Logitech PRO X SUPERLIGHT Wireless Gaming Mouse 25.6K dpi NVIDIA Reflex Black

Remove all obstacles that get in the way of victory with the lightest and fastest…

3 hours ago

Cooler Master Hyper 212 Halo² Black Edition RGB CPU Air Cooler Intel/AMD

Improved air flow with stunning dual loop ARGB lighting. Redesigned hybrid frame maintains stability without…

3 hours ago

PNY NVIDIA GeForce RTX 4060 Ti 8GB XLR8 VERTO EPIC-X RGB Ada Lovelace Graphics Card

NVIDIA® GeForce RTX™ 40 Series GPUs are beyond fast for gamers and creators. They're powered…

3 hours ago

Cooler Master Qube 500 Flatpack Macaron Edition Tempered Glass Mid-Tower ATX Case

The Qube 500 Flatpack case is a unique chassis to house your dream components. With…

3 hours ago

Seagate SkyHawk 8TB Network Surveillance/CCTV 3.5″ SATA HDD/Hard Drive

Designed to ensure seamless video footage capture in 24/7surveillance workloads that record video from 64…

3 hours ago