Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

Intel recommends updating to protect processors against critical vulnerability

Researchers found a vulnerability in some Intel processors that allows attackers to access encrypted data and install malicious firmware. When abused, the vulnerability opens the door to break through various security measures on the chip.

Intel is already aware of the issue and advised affected users to download the latest firmware update in order to protect their systems.

intel core i9-11900K
Intel

The vulnerability affects older Intel processors, including Intel Pentium, Celeron, and Atom, which are based on the Gemini Lake, Gemini Lake Refresh, and Apollo Lake platforms. Interestingly, it can only be exploited by hackers in physical possession of the chip — online-only access will not compromise the processor.

Recommended Videos

Due to this security flaw, capable hackers who have the affected chip on hand are allowed to run it in debugging and testing modules that are normally only used by firmware developers. This lets them completely bypass security measures, including Bitlocker and TPM protection, anti-copying blocks, and more.

Accessing developer mode allows the attacker to extract the data encryption key, which on Intel CPUs is normally stored in the TPM enclave. TPM stands for Trusted Platform Module and is a microcontroller used for storing keys, digital certificates, passwords, and other sensitive data. If TPM is being used to protect a Bitlocker key, using the processor in developer mode also lets the attacker breach that final wall of protection.

On top of gaining access to sensitive data, the hacker would also be able to breach the Intel Management Engine and run unauthorized firmware on the chip. The end result could be permanent access to the chip that could potentially go undetected for an undetermined amount of time.

A description of key derivation.
Image credit: Ars Technica Image used with permission by copyright holder

The entire process of gaining access to the processor and overcoming security measures takes just 10 minutes, which means that those with brief access to the chip are able to potentially cause a massive security breach in a very short time.

This vulnerability was first discovered and reported by researchers Mark Ermolov, Dmitry Sklyarov, and Maxim Goryachy. They reported it to Intel and talked about the vulnerability, revealing further details of the possible breach. Ars Technica then reported the situation in more detail.

“We found out that you can extract this key from security fuses. Basically, this key is encrypted, but we also found a way to decrypt it, and it allows us to execute arbitrary code inside the management engine, extract Bitlocker/TPM keys, etc.,” Goryachy told Ars Technica.

This isn’t the first time Intel products have been targeted by various hacking attempts. In 2020, the same research team found a possible vulnerability that allowed attackers to decrypt several Intel updates. There have also been flaws in the Intel Boot Guard and Software Guard Extensions.

Although Intel admits that the latest discovered vulnerability is dangerous and gave it a high severity rating, there have been no reports of users suffering from this security breach. Intel advises the owners of affected processors to simply install the latest firmware update in order to reinforce the security of their CPUs.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
More than seven months later, Intel CPU instability issue might be over
Intel's 14900K CPU socketed in a motherboard.

We first reported on the Intel CPU instability issue in February 2024, and since then, Intel has offered various fixes that helped, but still failed to fix the problem once and for all. Now, it finally seems like the owners of Intel's best CPUs might soon be able to rest easy. Intel has shared a new update that pinpoints the four causes of Raptor Lake problems and provides a fix.

Intel's July update on the matter disclosed that the company was aware of issues within the microcode and that the problem was related to incorrect voltages. Today's update breaks this down into four operating scenarios that can cause problems. Intel now refers to these long-lasting issues as the "Vmin Shift Instability."

Read more
Intel’s desktop CPU road map may have changed
Intel CEO Pat Gelsinger presents Intel's roadmap including Arrow Lake, Lunar Lake, and Panther Lake.

Intel's list of best processors is about to expand with the upcoming launch of Arrow Lake-S, also referred to as Intel Core Ultra 200-series for desktops. But what comes next is less certain, and even more so now. According to a post on the Chiphell forums, Intel may have decided to cancel the Arrow Lake-S refresh (Intel Core Ultra 300-series, presumably) that was reportedly slated for sometime next year as a follow-up to this year's initial launch. On the upside, the code name for an upcoming desktop CPU generation was also leaked.

The rumored Arrow Lake-S refresh was never confirmed, but there have been many whispers about it from various leakers. Much like the Raptor Lake refresh, it was never meant to be a groundbreaking update; the neural processing unit (NPU) was the main thing that was going to be updated.

Read more
Intel’s CPU lineups might get even more confusing
An Intel Core Ultra Series 2 chip embedded in a piece of glass.

Intel's list of processors constantly grows, and its whole new naming scheme just got even more confusing. Today's leaks imply that Intel might be working on another Raptor Lake refresh, this time under the Core 200 name. That's right -- just Core 200, without the Ultra. We also spotted some more budget-friendly, previously unheard-of Arrow Lake chips.

With Intel Arrow Lake right around the corner and Lunar Lake CPUs freshly out and available, Intel's got a lot going on in the CPU department right now, and there's more to come. Some non-Ultra Core 200 chips appeared in various Business Applications Performance Corporation (BAPCo) benchmarks, including the Core 7 250U, the Core 7 250H, and the Core 5 220H. There's also the Core 7 Ultra 255H, which is likely an upcoming Arrow Lake-H CPU set to appear inside next-gen laptops.

Read more