Intel processors have a vulnerability that affects BIOS boot
Does anyone know how many vulnerabilities Intel processors have been found to have? We've lost count and are getting all mixed up. And now we have to add a new one to all these Intel processor vulnerabilities . Security researchers have found a bug in Intel's CPU technologies that appears to have been patched.
According to the researchers, Intel would have patched this vulnerability last year, although we did not find out. We know it thanks to the report published by Positive Technologies, which has been released today. According to it: "most of the Intel chipsets released in the last five years contain the vulnerability in question"
[amazon box="B07STGGQ18"]New Intel vulnerability
The vulnerabilities, if exploited, we will not find out and the firmware patches largely correct the problem, but not completely. To avoid problems, the researchers indicate that the processors should be replaced with unaffected versions. As far as it is known, only the 10th Gen Intel would be exempt from this problem, although they are not yet sold.
This vulnerability has been technically named CVE-2019-0090. The vulnerability affects the Intel Converged Security and Management Engine (CSME). CSME is a security feature (yes, we see the irony too) built into the company's modern processors. This is based on cryptography for all technologies and firmware on the company's platforms.
Mark Ermolov, Principal Security Specialist at Positive Technologies highlights that CSME is one of the first elements to be executed. This system is responsible for cryptographically verifying and authenticating the firmware of the different controllers. CSME to top it off is "the cryptographic foundation" for all Intel technologies like EPID (Enhanced Privacy ID), Intel Identity Protection, firmware-based DRMs or TPMs.
Theoretically, in May 2019, the Intel SA-00213 update patches the root that generates the CSME vulnerability. This vulnerability was initially described as a firmware bug that allowed an attacker with physical access to scale privileges on the CPU.
Ermolov emphasizes that it can also be exploited by “local access”, or what is the same, an infected device. Such malware should have access to running the operating system code or BIOS-level code.
Source: zdnet