Intel Releases Patch For Nine Year Flaw In Workstation And Server Chips

Intel has patched a remote execution flaw in millions of its workstation and server chips that remained under the radar for nine years.

“There is an escalation of privilege vulnerability in Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 that can allow an unprivileged attacker to gain control of the manageability features provided by these products. This vulnerability does not exist on Intel-based consumer PCs,” explained Intel’s security advisory.

The vulnerability, which has been present since 2008, could allow hackers to gain system privileges in vulnerable computer hardware rather than need to go through the operating system, thus avoiding detection.

As Intel’s AMT allows access to a machine’s network hardware, an attacker could exploit the security hole and spread attacks to other systems on a network.

Hardware hack risk

Essentially, the bug, discovered and reported in  by Maksim Malyutin at Embedi in March and labled CVE-2017-5689, sits at the core of a computer’s silicon brain. This means that any malware exploits and hack attacks would be virtually impossible to detect as they site beyond the sight of anti-virus software and a machine’s operating system.

To squash the bug, a firmware update is needed to close the backdoor that looks to be present in millions of Intel chips and therefore millions of computers across the world.

Intel has a patch to fix the vulnerability, but people and businesses with affected machines will likely need to rely on the vendor of their computers and servers to push out the firmware update.

However, the chip maker has advised quick fixes in the from of rather complicated tweaks and disabling or removing the Local Manageability Service on affected systems.

In short, the vulnerability is a serious one and will require computer vendors to work on getting Intel’s firmware fix to customers using affected machines, though users of machines with consumer grade Intel chips appear to be unaffected by the flaw.

In a minor twist if irony, the flaw comes at a time when Intel is spinning out is security division into the reinvigorated McAfee brand.

As life time in chips: what do you know about Intel?

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

2 days ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

2 days ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

2 days ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

3 days ago

Former Policy Boss At X, Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

3 days ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

3 days ago