Intel Vulnerability Enables Multiple Issues

Intel Vulnerability Enables Multiple Issues

Intel is warning users of a high severity flaw found within their firmware of it’s ‘Converged Security and Management Engine’ (CSME) which is used to power Intel’s ‘Active Management System’ hardware for the purpose of remote out-of-band management to consumers. This flaw could enable an attacker to conduct Privilege Escalation, Information Disclosure and Denial of Service.

exc-5e4a5d5fdd42c458f374aa78

Intel is warning users of a high severity flaw found within their firmware of it’s ‘Converged Security and Management Engine’ (CSME) which is used to power Intel’s ‘Active Management System’ hardware for the purpose of remote out-of-band management to consumers. This flaw could enable an attacker to conduct Privilege Escalation, Information Disclosure and Denial of Service.

“Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.” – Intel Advisory

The recommended route to remediate this issue is by updating the CSME version to it’s latest. The issues were found internally by Intel themselves thanks to Chedva Gottesman.

This was not the only vulnerability identified within Intel’s Products. In total there were six patched flaws on Tuesday including the mentioned high severity flaw within CSME.

The other five remaining vulnerabilities included a Medium severity flaw within Intel’s Renesas Electronics USB 3 driver that is common to Intel motherboards. This issue could potentially allow privilege escalation and comes from improper permissions in the installer. All versions of the driver have been affected by this issue.

“Intel has issued a Product Discontinuation notice for Intel Renesas Electronics USB 3.0 Driver and recommends that users of the Intel Renesas Electronics USB 3.0 Driver uninstall it or discontinue use at their earliest convenience,”

Another two Medium severity flaws exist within Intel’s RAID Web Console which could potentially allow users to configure the RAID custom storage controllers and the disk drives on the system. One of the Medium severity flaws is found in RAID Web Console 3 for Windows, which can be found from the improper permissions set in the installer. The other Medium severity can be found in RAID Web Console 2 which is also found from set improper permissions within the installer.

The final Medium severity flaw can be found in Intel Manycore Platform Software Stack, which is necessary to run Intel Xeon Phi Coprocessor which enables privilege escalation from improper permissions in the installer.

The sixth vulnerability comes from a flaw within Intel’s Software Guard Extension (SGX) SDK which again could enable privilege escalation.

  • Latest Articles
Author Details
Penetration Tester at Hedgehog Security

Michael is an OSCP qualified Penetration Tester based in our Gibraltar office. Outside of work Michael is a keen power lifter and photographer.

  • Cisco’s recent update fixes high-severity flaws
  • Ukrainian Malware Spreading Exposed on Dark Web

    Malware is known as ‘Blackout’ was found in Ukraine in 2015 affecting power plants and in turn causing blackouts. This specific malware target SSH keys to gain access to the victim’s machine unnoticed.

  • Intel Vulnerability Enables Multiple Issues

    Intel is warning users of a high severity flaw found within their firmware of it’s ‘Converged Security and Management Engine’ (CSME) which is used to power Intel’s ‘Active Management System’ hardware for the purpose of remote out-of-band management to consumers. This flaw could enable an attacker to conduct Privilege Escalation, Information Disclosure and Denial of Service.

  • Dell SupportAssist-ing Hackers

    A recent vulnerability found in Dell’s SupportaAssist software found that if exploited correctly can lead to code execution for unprivileged users. This is known as an uncontrolled search path vulnerability (CVE-2020-5316).

  • Android Bluetooth Critical RCE Flaw

    A recent vulnerability was found by researchers from a German security firm. Fixes are available via the Android February 2020 Security Bulletin. The bug is identified as CVE-2020-002; when exploited can result in remote-code-execution without any user interaction with elevated privileges.

  • WhatsApp? WhatsPatch? WhatsCrack? | WhatsApp Critical Flaw

    A security researcher by the name of Gal Weizman from PerimeterX found multiple flaws within WhatsApp that could potentially lead to remote-code-execution (RCE). The flaws enabled vulnerabilities such as Open-Redirect, Persistent-XSS, CSP-Bypass and read privileges from the Local File System (LFS).

  • Google Exposed Personal Photos

    It has recently been reported that not long ago, last Thanksgiving, Google had a bug which caused personal photos to be shared to complete strangers. ‘The Chocolate Factory’ made note of this issue and began notifying users that there is a bug in Google Photos data-archiving tool, Takeout.

  • Handout the CacheOut

    A recent finding of a microarchitectural Data Sampling (MDS) vulnerability within Intel’s CPU’s found by researchers have now released a Proof-of-Concept (PoC) code. This was not the only recent vulnerability found; however, it is the most severe with a Medium risk vulnerability.

  • Juice Jacking? The New but Old Revolution of Hacking Attacks!

    Juice Jacking is an attack-type that involves plugging your phone into public sockets for “charging purposes”. The truth behind these sockets is the installation of malware on your phones and other electronic devices of unsuspecting users.

  • Mistakes were Made | Intel Privilege Escalation

    Intel is a very large corporation most known for their processors. A recent flaw within Intel’s ‘VTune Profiler’ software could enable anyone to upgrade their privileges if exploited correctly. This software is a performance monitoring & analysis application mainly used for serial and multi threaded application developers.

Share on facebook
Facebook
Share on google
Google+
Share on twitter
Twitter
Share on linkedin
LinkedIn
Share on pinterest
Pinterest
Scroll to Top