Skip to main content

Uh-oh! There’s an unfixable security vulnerability in Intel processors

A security issue that could affect almost all Intel processors released in the last five years has been discovered. Researchers at the security firm Positive Technologies found an error in a system called the Intel Converged Security and Management Engine (CSME), as well as in the hardware of the chips themselves.

The CSME system is used in a large number of processes on the chips, including initial authentication, and is the basis for various hardware security technologies used on Intel chipsets. It may be impossible to fully secure against this vulnerability.

“This vulnerability jeopardizes everything Intel has done to build the root of trust and lay a solid security foundation on the company’s platforms,” the researchers wrote in a blog post. “The problem is not only that it is impossible to fix firmware errors that are hard-coded in the Mask ROM of microprocessors and chipsets. The larger worry is that, because this vulnerability allows a compromise at the hardware level, it destroys the chain of trust for the platform as a whole.”

Security researcher Mark Ermolov gave more details about the vulnerability in a statement: “The vulnerability resembles an error recently identified in the BootROM of Apple mobile platforms, but affects only Intel systems. Both vulnerabilities allow extracting users’ encrypted data.

“Here, attackers can obtain the key in many different ways. For example, they can extract it from a lost or stolen laptop in order to decrypt confidential data. Unscrupulous suppliers, contractors, or even employees with physical access to the computer can get hold of the key. In some cases, attackers can intercept the key remotely, provided they have gained local access to a target PC as part of a multistage attack, or if the manufacturer allows remote firmware updates of internal devices, such as Intel Integrated Sensor Hub.”

Intel has issued a patch to mitigate the issue, which should make it harder for hackers to take advantage of the vulnerability. However, the security issue cannot be completed fixed through software patching. To completely secure against the issue, short of buying a new processor, Positive Technologies recommends disabling Intel CSME-based encryption of data storage devices.

If you are concerned about the security of your Intel chip, there is a page of information and recommendation on Intel’s website that you can check for guidance.

Editors' Recommendations

Georgina Torbet
Georgina is the Digital Trends space writer, covering human space exploration, planetary science, and cosmology. She…
Intel Raptor Lake CPUs: Everything we know about the 13th-gen processors
Intel Core i5-13600K installed in a motherboard.

Raptor Lake is Intel's 13th generation of processors, and it's one of the most exciting hardware launches of the year. Following up on the momentum it built with its Alder Lake line of CPUs, Intel is looking to retain some of the hard-fought performance crowns. It's got new and stiffer competition, though, in the form of AMD's Ryzen 7000 series of Zen 4 CPUs, which have already impressed for their efficiency and performance.

How will these new CPU lines fair when going head to head? Here's everything you need to know about Raptor Lake.
Pricing and availability

Read more
Intel XeSS is already disappointing, but there’s still hope
Intel XeSS visualized.

Intel's hotly anticipated Xe Supersampling (XeSS) tech is finally here, and a couple weeks before Intel's Arc Alchemist GPUs show up. It's available now in Death Stranding and Shadow of the Tomb Raider, and more games are sure to come. But right now, it's really difficult to recommend turning XeSS on.

Bugs, lacking performance, and poor image quality have sent XeSS off to a rough start. Although there are glimmers of hope (especially with Arc's native usage of XeSS), Intel has a lot of work ahead to get XeSS on the level of competing features from AMD and Nvidia.
Spotty performance

Read more
Intel reveals official Arc Alchemist specs, and there’s one major surprise
Intel Arc A770 graphics card.

Today is a big day for Intel Arc Alchemist -- the official specifications of the graphics cards have finally been revealed, confirming some previous speculation, but not without one unexpected announcement.

Although Intel has mostly focused on the Arc A770 and the Arc A750, it will actually launch another GPU, too, the seemingly forgotten Arc A580. What can we expect from these GPUs and will they be competitive enough to capture the interest of Nvidia and AMD customers?

Read more