Site icon WinCert

A new security flaw affecting Intel CPU’s has been discovered

<p>Researchers from a cybersecurity company Positive Technologies has just discovered a new security flaw affecting all Intel CPU&&num;8217&semi;s released in the last five years&period; The new vulnerability was discovered in Intel&&num;8217&semi;s Converged Security and Management Engine &lpar;CSME&rpar; ROM which is a subsystem that validates the firmware running on Intel-based computers&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3577" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2020&sol;03&sol;intel-3064506&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"426" &sol;><&sol;p>&NewLine;<p>The <a href&equals;"https&colon;&sol;&sol;blog&period;ptsecurity&period;com&sol;2020&sol;03&sol;intelx86-root-of-trust-loss-of-trust&period;html" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">report shows<&sol;a> that this vulnerability cannot be fixed by firmware updates and that it sets the stage for arbitrary code execution in Intel&&num;8217&semi;s CSME&period; Luckily&comma; Intel&&num;8217&semi;s 10th Gen CPU chips are not affected by this flaw&period;<&sol;p>&NewLine;<p>This flaw threatens Intel&&num;8217&semi;s efforts in building a root of trust and laying a solid security foundation on the company&&num;8217&semi;s platforms&period; Unfortunately&comma; it is impossible to fix firmware errors that are hard-coded in the Mask ROMs and thus the system can be compromised at the hardware level by possibly destroying the chain of trust for the whole platform&comma; as explained by Positive Technologies&period;<&sol;p>&NewLine;<p>Intel is not too much worried about this vulnerability as the attacker would require physical access and special hardware to take advantage of this flaw&period; The company also said that it has released mitigations and advises keeping the systems up-to-date even though researchers from Positive Technologies said that this flaw cannot be fixed&period;<&sol;p>&NewLine;

Exit mobile version