Skip to main content
  1. Home
  2. Computing
  3. News

Intel AMT firmware suffers security flaw even when machines are off

Add as a preferred source on Google

Another security vulnerability has been revealed that poses a significant risk for a number of PCs running Intel chipsets or processors. This one’s a bit different — and potentially more dangerous — than many other vulnerabilities in that it targets business-class systems in particular. It can also affect machines that aren’t even running.

The flaw, which exists in certain Intel chipset firmware versions utilized by some systems with vPro processors, affects the Active Management Technology, or AMT, feature. AMT lets administrators manage machines via remote connections, and the vulnerability allows attackers to bypass authentication and utilize the same capabilities, Ars Technica reports.

Recommended Videos

AMT is a part of the remote access features of some systems that allow remote access to a machine even when it’s shut down. As long as such a machine has power, it can by design be accessed with all the intended remote capabilities enabled.

Intel designed AMT to demand a password before allowing remote access via web browser. Unfortunately, the flaw allows attackers to bypass the AMT system’s usual authentication requirement. Tenable Network Security, which has created what it characterizes as the first Intel AMT vulnerability detection capability, describes the flaw as follows:

” … we reduced the response hash to one hex digit and authentication still worked. Continuing to dig, we used a NULL/empty response hash (response=”” in the HTTP Authorization header). Authentication still worked. We had discovered a complete bypass of the authentication scheme.”

As Ars Technica points out, the issue is made even worse by the AMT feature’s design, in which network traffic is passed through the Intel Management Engine and to the AMT, bypassing the operating system. That means that there’s no record of unauthorized access.

Intel indicated in a blog post that PC manufacturers should be releasing patches for affected systems within the week. It also posts a tool to locate and diagnose vulnerable systems. Fujitsu, HP, and Lenovo have provided information on their own affected systems. So far, the Shodan security search engine has located more than 8,500 machines that are vulnerable to attack.

Updated on 5-10-2017 by Mark Coppock: Clarified that the flaw exists in certain chipset firmware and not inherent in Intel vPro processors and removed the incorrect reference to any empty text field being able to bypass AMT authentication.

Mark Coppock
Former Computing Writer
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
LG agrees to kill McAfee pop-up on Windows PCs after Microsoft steps in
It's a quick fix, not a real one, since the pipeline that let LG install the pop-up is still wide open.
LG UltraGear 45gx950b

Plug in an LG monitor, and Windows might quietly install more than a driver. That's what several owners found out this month, when a pop-up promoting a McAfee antivirus trial appeared on their screens without a single consent prompt in sight. Microsoft has now stepped in, and LG says it's turning off the ad.

Where the pop-up came from

Read more
Firefox just made work and personal browsing easier to separate
Containers are now built into Firefox to keep work and personal accounts separate
mozilla-firefox

Mozilla has released Firefox 153, giving people a built-in way to keep work, personal, shopping, and banking activity apart. The update began rolling out to Release channel users on July 21 and also introduces HDR video playback on Windows, PDF improvements, and tighter controls over local files and network devices.

Containers open tabs in isolated spaces where cookies, logins, and site storage are not shared. Someone can remain signed into two accounts on the same website, keep a work Google account away from personal YouTube activity, or stop shopping cookies from following everyday browsing.

Read more
ChatGPT can now connect to your Apple Health data to give more personalized health answers
OpenAI brings personalized health conversations to ChatGPT
Health in ChatGPT

OpenAI is expanding ChatGPT into a new category with the launch of Health in ChatGPT, a feature that allows users to securely connect health information from Apple Health and supported medical records. The feature is rolling out to users in the United States and is designed to help people ask health-related questions with more personalized context, instead of relying on isolated conversations.

According to OpenAI, more than 300 million people use ChatGPT every week for health-related queries, ranging from understanding lab reports to preparing for doctor appointments.

Read more