Skip to main content

Researchers find vulnerability in older versions of Intel ME, but you probably don't need to worry

According to security researcher Damien Zammit, there’s possibility that computers based on recent x86-based processors from Intel could be unknowingly compromised. The good news, however, is that there’s no known exploit currently in use, so don’t panic just yet.

Most general consumers purchasing Intel-based desktops and laptops have no clue that a special 32-bit ARC microprocessor is built inside Intel’s supporting motherboard chipset. It’s part of the Intel Management System (ME), and acts like a standalone, independent “computer” that controls the Intel x86 processor. Its main focus is big enterprise deployments, so that multiple systems can be managed remotely.

Recommended Videos

That said, ME is invisible in regards to the overall system setup, and in some cases includes Intel’s Active Management Technology (AMT) so that it can continue to perform no matter what operating system is installed. Thanks to AMT, the ME system can sneak past the x86 Intel processor and access any region of the system memory. It also runs its own TCP/IP server, which is capable of bypassing an installed firewall to send and receive packets. The ME system cannot be disabled by the installed operating system or x86-based firmware, especially on systems that are newer than the Intel Core 2 processor series.

Thus, because Intel-based systems essentially depend on ME to boot, the ME firmware is verified by a boot ROM that’s secretly embedded in the Intel chipset. This process matches the public key’s SHA256 checksum with one provided by the factory, and then verifies the RSA signature of the firmware payload, a process that can’t be bypassed. The ME firmware is cryptographically protected with RSA 2048. If the ME firmware is not present or somehow becomes corrupted, the system will either shut down right after booting, or will refuse to boot altogether.

So, the big stink regarding Intel’s ME system is that researchers reportedly managed to exploit weaknesses in the firmware, enabling them to take partial control of ME installed on early platforms. That means there’s a possibility that attackers can slip under the radar and use a rootkit to quietly gain administrative access to an Intel-based computer. But this possibility is theoretical, and the research only applies to an older version of Intel ME.

“Personally, I would like if my ME only did the most basic task it was designed for, set up the bus clocks, and then shut off,” writes Damien Zammit. “This way, it would never be able to talk out of the network card with some of my personal data.”

At its heart, this controversy is about a difference in opinion about security best practices. Intel’s ME takes a locked-down approach. Only the company knows how it works. That makes it harder to attack, but it also makes it harder to mitigate the possible damage of an attack, and means there’s no way to know — for sure — how it’s working. Zammit supports an open-sourced approach. He believes its “inevitable” that ME will fall to an exploit, and once that happens, it’ll be open season on Intel machines.

However, it’s worth noting that open-source security has a rocky track record of its own. The infamous “Heartbleed” bug, which made it possible to steal information out of the secured OpenSSL protocol, is a good example. In other words, Zammit’s idea that Intel ME would be better off if Intel let others know about its details is an opinion, not a fact.

So, if you have an Intel processor, don’t worry. There’s no known exploit being used at this time. And not all Intel processors have the chip — only those that support vPro functionality include it.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
AMD CPUs should support CUDIMM memory soon, but not this generation
Official product render of the G.Skill Trident Z5 Neo memory for AMD.

AMD processors can't make full use of CUDIMM memory just yet, but it may well do before the end of this socket. In a recent interview with DigitalTrends, AMD's product management lead for gaming and workstations, Sourabh Dhir, told us that there was no reason that AM5 couldn't support CUDIMM, but wouldn't be draw on a timeline of when we might see it.

Considering we expect AM5 to be AMD's flagship CPU socket for the next couple of generations at least, that probably means we don't have long to wait for the added memory speed support.

Read more
Asus’ new RTX 5090 might be the most ridiculous GPU ever, and it costs $10,000
RTX 5090 Dhahab Edition.

It's no news that Nvidia makes some of the best graphics cards, and Asus is one of its most prominent partners. However, this time the company truly took things to the next level by launching an RTX 5090 that just might be the most ridiculous GPU I've ever seen. Prices range from $7,000 to over $10,500, and there's a good reason for that ... kind of.

The unique Asus ROG Astral RTX 5090 "Dhahab Edition" draws inspiration from the Middle East. In the announcement, Asus says that the card blends modern technology and cultural heritage, reflecting the rapid growth of the Middle East."

Read more
MSI’s powerful Steam Deck rival gets a global release and higher price tag
MSI Claw 8 connected to a monitor

The MSI Claw 8 AI+ Polar Tempest model first launched in April before being removed from MSI's website, but has now returned with a dedicated product listing and a July 15 release date for the United States. This powerful handheld leaves the Steam Deck in the dust in most regards, but has been notably hard to purchase due to high demand and a limited initial production run.

The latest run of the Polar Tempest Edition comes with 2TB of storage and is priced at $999, versus the original Sandstorm model with 1TB of storage and an $899 price tag. In addition to a US release, fans have spotted listings in Germany, which suggest Europe will also get another release this summer. The only other difference is the white front panels (hence the Polar moniker).

Read more