ZeroHour
Security Affairspublished ()ingested @securityaffairs

Experts found an undocumented Kill Switch in Intel Management Engine

criticalVulnerabilityimportance 60CVE-2017-5689

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-5689
Unauthenticated Privilege Escalation in Intel AMT, ISM, and SBT Manageability Firmware

CVE-2017-5689 is a critical (CVSS 9.8) privilege escalation flaw in the manageability features of the Intel Management Engine: Active Management Technology (AMT), Standard Manageability (ISM), and Small Business Technology (SBT), which ship with Intel vPro-class business platforms. An unprivileged remote attacker can exploit it by sending crafted unauthenticated requests to the AMT/ISM network interface (typically TCP ports 16992/16993) on a provisioned system, gaining full system/administrative privileges with no credentials or user interaction. Alternatively, an unprivileged local attacker can provision the manageability features to gain system privileges on AMT, ISM, and SBT. Affected systems include business PCs and workstations with AMT/ISM enabled, plus OEM implementations such as HPE ProLiant ML10 Gen9 servers and a wide range of Siemens SIMATIC industrial PCs, controllers, and panel firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-28, ransomware use unknown), has a public PoC (Embedi's 'Silent Bob is Silent'), and carries a 92.2% EPSS probability of exploitation, so it should be treated as actively exploited.

Do: Update Intel Management Engine/AMT firmware to the fixed versions released under Intel's May 2017 advisory (SA-00075) via your OEM — apply HPE ProLiant ML10 Gen9 and Siemens SIMATIC firmware updates per vendor instructions, as required by CISA KEV. Until patched, block or restrict ports 16992/16993 at the perimeter, keep AMT confined to trusted management networks, or disable AMT/SBT where not required, and verify provisioned systems with Intel's detection guidance.

9.892% KEV PoC
  • Intel Active Management Technology (AMT)
  • Intel Standard Manageability (ISM)
  • Intel Small Business Technology (SBT)
  • +9 more
masstens of millions of vPro-enabled endpoints ship with AMT/ISM, of which hundreds of thousands were directly exposed to the internet
Full article592 words · extracted from securityaffairs.com · click to collapse

Security researchers at Positive Technologies have discovered an undocumented configuration setting that disables the Intel Management Engine.

Security researchers at Positive Technologies have discovered an undocumented configuration setting that disables the CPU control mechanism Intel Management Engine 11.

The Intel Management Engine consists of a microcontroller that works with the Platform Controller Hub chip, in conjunction with integrated peripherals, it is a critical component that handles data exchanged between the processor and peripherals.

For this reason, security experts warned in the past of the risks for Intel Management Engine vulnerabilities. An attacker can exploit a flaw in the Intel ME to establish a backdoor on the affected system and gain full control over it.

In May, security experts discovered a critical remote code execution (RCE) vulnerability, tracked as CVE-2017-5689, in the remote management features implemented on computers shipped with Intel Chipset in past 9 years.

The vulnerability affects the Intel Management Engine (ME) technologies such as Active Management Technology (AMT), Small Business Technology (SBT), and Intel Standard Manageability (ISM) and could be exploited by hackers to remotely take over the vulnerable systems.

An unofficial workaround dubbed ME Cleaner can bypass Intel ME, but it is not able to turn off it.

“Intel ME is a coprocessor integrated in all post-2006 Intel boards, for which this Libreboot page has an excellent description. The main component of Intel ME is Intel AMT, and I suggest you to read this Wikipedia page for more information about it. In short, Intel ME is an irremovable environment with an obscure signed proprietary firmware, with full network and memory access, which poses a serious security threat. Even when disabled from the BIOS settings, Intel ME is active: the only way to be sure it is disabled is to remove its firmware from the flash chip.” reads the project description.

Now the experts from Positive Technologies (Dmitry Sklyarov, Mark Ermolov, and Maxim Goryachy) discovered a way to disable the Intel Management Engine 11 via an undocumented mode.

The researchers discovered that it is possible to turn off the Intel ME by setting the undocumented high assurance platform (HAP) bit to 1 in a configuration file.

Intel Management Engine

The experts discovered that the security framework was developed by the US National Security Agency … yes the NSA!

“One of the fields, called “reserve_hap”, drew our attention because there was a comment next to it: “High Assurance Platform (HAP) enable.” continues the analysis. “Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA). A graphics-rich presentation describing the program can be found here.”

Below the statement released by Intel in response to a request for comment.

“In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features,” Intel’s spokesperson said. “In this case, the modifications were made at the request of equipment manufacturers in support of their customer’s evaluation of the US government’s ‘High Assurance Platform’ program. These modifications underwent a limited validation cycle and are not an officially supported configuration.”

Positive Technologies also noted that the HAP affect on Boot Guard, Intel’s boot process verification system, is still undocumented.

“We also found some code in BUP that, when HAP mode is enabled, sets an additional bit in Boot Guard policies. Unfortunately, we have not succeeded in finding out what this bit controls.” concluded the experts.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Intel Management Engine, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/62470/hacking/intel-management-engine-kill-switch.html