ZeroHour
CyberScooppublished ()ingested @WatermanReports

Intel chip vulnerability sends corporate cyber teams scrambling

criticalVulnerability exploited in the wildimportance 60CVE-2017-5689

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-5689
Unauthenticated Privilege Escalation in Intel AMT, ISM, and SBT Manageability Firmware

CVE-2017-5689 is a critical (CVSS 9.8) privilege escalation flaw in the manageability features of the Intel Management Engine: Active Management Technology (AMT), Standard Manageability (ISM), and Small Business Technology (SBT), which ship with Intel vPro-class business platforms. An unprivileged remote attacker can exploit it by sending crafted unauthenticated requests to the AMT/ISM network interface (typically TCP ports 16992/16993) on a provisioned system, gaining full system/administrative privileges with no credentials or user interaction. Alternatively, an unprivileged local attacker can provision the manageability features to gain system privileges on AMT, ISM, and SBT. Affected systems include business PCs and workstations with AMT/ISM enabled, plus OEM implementations such as HPE ProLiant ML10 Gen9 servers and a wide range of Siemens SIMATIC industrial PCs, controllers, and panel firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-28, ransomware use unknown), has a public PoC (Embedi's 'Silent Bob is Silent'), and carries a 92.2% EPSS probability of exploitation, so it should be treated as actively exploited.

Do: Update Intel Management Engine/AMT firmware to the fixed versions released under Intel's May 2017 advisory (SA-00075) via your OEM — apply HPE ProLiant ML10 Gen9 and Siemens SIMATIC firmware updates per vendor instructions, as required by CISA KEV. Until patched, block or restrict ports 16992/16993 at the perimeter, keep AMT confined to trusted management networks, or disable AMT/SBT where not required, and verify provisioned systems with Intel's detection guidance.

9.892% KEV PoC
  • Intel Active Management Technology (AMT)
  • Intel Standard Manageability (ISM)
  • Intel Small Business Technology (SBT)
  • +9 more
masstens of millions of vPro-enabled endpoints ship with AMT/ISM, of which hundreds of thousands were directly exposed to the internet
Full article775 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Corporate IT departments across the globe are scrambling to figure out if their networks are affected by a vulnerability in Intel processors that opened the chips up to hackers.

(Daniel Oines / Flickr)

Corporate IT departments across the globe were scrambling Tuesday to figure out if their networks were hit by a vulnerability in Intel processors that opened the chips up to hackers.

Intel announced the existence of vulnerability CVE-2017-5689 in its Active Management Technology, or AMT, firmware on Monday, saying it had not been exploited in the wild.

“An unprivileged network attacker could gain system privileges,” by remotely exploiting the vulnerability, the company said, revealing that it impacted chips shipped since 2008, but not ones used in consumer personal computers.

“Yes, this is terrifying,” wrote security researcher Matthew Garrett on his blog.

If hackers learned how to exploit the vulnerability — which Intel rated “critical”— they would have access to the powerful features of AMT, a technology designed to let the IT department of a company remotely manage large numbers of computers.

“AMT provides a web [user interface] that allows you to do things like reboot a machine, provide remote install media or even… get a remote console,” explained Garrett.

Importantly, these “out of band” management tools work on the computer below the level of the operating system — completely out of view of any security software or anti-malware protection.

“God help you if this service is exposed to the public internet,” commented the British tabloid IT trade news publication The Register.

But an Intel spokesman told CyberScoop there was no evidence anyone had actually used the security flaw to break into any computers.

“We are not aware of any exploitation of this vulnerability,” William Moss said via email.

Waiting on vendors

Intel learned of the vulnerability last month, from a security researcher called Maksim Malyutin and had moved immediately to get a fix in place, he told CyberScoop.

“We have implemented and validated a firmware update to address the problem, and we are cooperating with equipment manufacturers to make it available to end-users as soon as possible,” Moss said.

And there’s the rub. Because the Intel chips were shipped in computers made by dozens of different manufacturers, end-users will have to wait until their vendor provides the firmware update. Assuming that their products are still being supported by the manufacturer.

No figures were immediately available for the total number of chips affected, and security researchers spent Monday debating how widely exploitable the vulnerability might be in real life.

“Most Intel systems don’t ship with AMT. Most Intel systems with AMT don’t have it turned on,” wrote Garrett. He told CyberScoop it would be impossible to know exactly how many machines might be impacted without more detailed information from Intel.

“The number of machines with AMT enabled and accessible to the outside world is probably pretty tiny,” he said via Twitter. Indeed one estimate compiled using the Shodan search engine by security researcher HD Moore, reported by Ars Technica, put the number at fewer than 7000.

“But they are almost certainly corporate networks, where this [vulnerability] could be used to spread from a single machine to others,” added Garrett.

Corporate end-users can consult Intel’s advisory and detection guide to find out if they are affected. If they are, they should check the mitigation guide for advice on temporarily blocking the vulnerability while waiting for a firmware patch from the manufacturer.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/patch-terrifying-intel-chip-vulnerability-amt/