Author Topic: Intel finds critical holes in secret Management Engine  (Read 157 times)

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 10427
Intel finds critical holes in secret Management Engine
« on: November 21, 2017, 06:53:55 AM »

Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets


Bugs can be exploited to extract info, potentially insert rootkits

https://www.theregister.co.uk/2017/11/20/intel_flags_firmware_flaws/

Intel Product Security Center
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr

Detection Tool:
https://downloadcenter.intel.com/download/27150
« Last Edit: November 21, 2017, 01:38:15 PM by Bugbatter »

Microsoft MVP Consumer Security 2006-2016
Microsoft Windows Insider MVP 2016-

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 10427
Re: Intel finds critical holes in secret Management Engine
« Reply #1 on: November 25, 2017, 07:53:04 AM »

I am glad to learn that Lenovo issued patches in a timely manner. I have not had a chance to check the other OEM's yet.

Microsoft MVP Consumer Security 2006-2016
Microsoft Windows Insider MVP 2016-

Offline joe53

  • Dell Community Colleague
  • SpywareHammer Staff
  • Bronze Member
  • Posts: 243
  • Certifiable
    • Free PC Security Software- A Primer
Re: Intel finds critical holes in secret Management Engine
« Reply #2 on: November 25, 2017, 09:47:19 PM »
Dell Client Statement on Intel ME/TXE Advisory (INTEL-SA-00086):
https://www.dell.com/support/article/us/en/19/sln308237/dell-client-statement-on-intel-me-txe-advisory--intel-sa-00086-?lang=en

Unfortunately my Dell XPS 13 is affected, and the timeline for a fix by Dell in the above link is "TBD".
 :(1

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 10427

Microsoft MVP Consumer Security 2006-2016
Microsoft Windows Insider MVP 2016-