ZeroHour
Security Affairspublished ()ingested @securityaffairs

A critical RCE flaw in Intel Management Engine affects Intel enterprise PCs dates back 9 years

criticalVulnerabilityimportance 60CVE-2017-5689

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-5689
Unauthenticated Privilege Escalation in Intel AMT, ISM, and SBT Manageability Firmware

CVE-2017-5689 is a critical (CVSS 9.8) privilege escalation flaw in the manageability features of the Intel Management Engine: Active Management Technology (AMT), Standard Manageability (ISM), and Small Business Technology (SBT), which ship with Intel vPro-class business platforms. An unprivileged remote attacker can exploit it by sending crafted unauthenticated requests to the AMT/ISM network interface (typically TCP ports 16992/16993) on a provisioned system, gaining full system/administrative privileges with no credentials or user interaction. Alternatively, an unprivileged local attacker can provision the manageability features to gain system privileges on AMT, ISM, and SBT. Affected systems include business PCs and workstations with AMT/ISM enabled, plus OEM implementations such as HPE ProLiant ML10 Gen9 servers and a wide range of Siemens SIMATIC industrial PCs, controllers, and panel firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-28, ransomware use unknown), has a public PoC (Embedi's 'Silent Bob is Silent'), and carries a 92.2% EPSS probability of exploitation, so it should be treated as actively exploited.

Do: Update Intel Management Engine/AMT firmware to the fixed versions released under Intel's May 2017 advisory (SA-00075) via your OEM — apply HPE ProLiant ML10 Gen9 and Siemens SIMATIC firmware updates per vendor instructions, as required by CISA KEV. Until patched, block or restrict ports 16992/16993 at the perimeter, keep AMT confined to trusted management networks, or disable AMT/SBT where not required, and verify provisioned systems with Intel's detection guidance.

9.892% KEV PoC
  • Intel Active Management Technology (AMT)
  • Intel Standard Manageability (ISM)
  • Intel Small Business Technology (SBT)
  • +9 more
masstens of millions of vPro-enabled endpoints ship with AMT/ISM, of which hundreds of thousands were directly exposed to the internet
Full article502 words · extracted from securityaffairs.com · click to collapse

A critical remote code execution vulnerability tracked as CVE-2017-5689 in Intel Management Engine affects Intel enterprise PCs dates back 9 years.

A critical remote code execution (RCE) vulnerability tracked as CVE-2017-5689 has been discovered in the remote management features implemented on computers shipped with Intel Chipset in past 9 years.

The vulnerability affects the Intel Management Engine (ME) technologies such as Active Management Technology (AMT), Small Business Technology (SBT), and Intel Standard Manageability (ISM) and could be exploited by hackers to remotely take over the vulnerable systems.

The remote management features allow system administrators to remotely manage computers over an enterprise network. Such kind of features are implemented only in enterprise solutions and doesn’t affect chips running on Intel-based consumer PCs.

“There is an escalation of privilege vulnerability in Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 that can allow an unprivileged attacker to gain control of the manageability features provided by these products.  This vulnerability does not exist on Intel-based consumer PCs. ” reads the advisory published by Intel.

The vulnerability rated by Intel as highly critical, could be exploited in two ways:

  1. An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel® Active Management Technology (AMT) and Intel® Standard Manageability (ISM).
    • CVSSv3 9.8 Critical /AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  2. An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology (SBT).
    • CVSSv3 8.4 High /AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An attacker can exploit the vulnerability to remotely access the vulnerable machine and perform in a stealth way malicious activities, including to deliver a malware.

The flaw was first reported in March by the security expert Maksim Malyutin of Embedi.

These flawed remote management features have been implemented in many Intel chipsets for nine years, starting from Nehalem Core i7 in 2008. Modern Apple Macs do not ship with the AMT software, so they are not affected.

This kind of flaw is very insidious because any countermeasure implemented at the operating system level is not able to detect malicious operation because AMT has direct access to the computer’s network hardware. Malicious traffic is routed directly to the Management Engine and passed on to AMT, but the local OS never sees it.

According to Intel, the remote code execution vulnerability affects Intel manageability firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 for Intel’s AMT, ISM, and SBT platforms. Versions before 6 or after 11.6 are not impacted.

Intel promptly released new firmware versions along with a detection guide to check if a system is vulnerable. The company also shared a mitigation guide that is essential for those organizations that can not immediately install updates.

The chipmaker is recommending vulnerable customers install a firmware patch as soon as possible.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Intel Management Engine, hacking)

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/58656/hacking/intel-management-engine.html