Skip to main content

Uh-oh! There’s an unfixable security vulnerability in Intel processors

A security issue that could affect almost all Intel processors released in the last five years has been discovered. Researchers at the security firm Positive Technologies found an error in a system called the Intel Converged Security and Management Engine (CSME), as well as in the hardware of the chips themselves.

The CSME system is used in a large number of processes on the chips, including initial authentication, and is the basis for various hardware security technologies used on Intel chipsets. It may be impossible to fully secure against this vulnerability.

“This vulnerability jeopardizes everything Intel has done to build the root of trust and lay a solid security foundation on the company’s platforms,” the researchers wrote in a blog post. “The problem is not only that it is impossible to fix firmware errors that are hard-coded in the Mask ROM of microprocessors and chipsets. The larger worry is that, because this vulnerability allows a compromise at the hardware level, it destroys the chain of trust for the platform as a whole.”

Security researcher Mark Ermolov gave more details about the vulnerability in a statement: “The vulnerability resembles an error recently identified in the BootROM of Apple mobile platforms, but affects only Intel systems. Both vulnerabilities allow extracting users’ encrypted data.

“Here, attackers can obtain the key in many different ways. For example, they can extract it from a lost or stolen laptop in order to decrypt confidential data. Unscrupulous suppliers, contractors, or even employees with physical access to the computer can get hold of the key. In some cases, attackers can intercept the key remotely, provided they have gained local access to a target PC as part of a multistage attack, or if the manufacturer allows remote firmware updates of internal devices, such as Intel Integrated Sensor Hub.”

Intel has issued a patch to mitigate the issue, which should make it harder for hackers to take advantage of the vulnerability. However, the security issue cannot be completed fixed through software patching. To completely secure against the issue, short of buying a new processor, Positive Technologies recommends disabling Intel CSME-based encryption of data storage devices.

If you are concerned about the security of your Intel chip, there is a page of information and recommendation on Intel’s website that you can check for guidance.

Editors' Recommendations

Georgina Torbet
Georgina is the Digital Trends space writer, covering human space exploration, planetary science, and cosmology. She…
Intel Raptor Lake could deliver a 60% performance upgrade, but there’s a catch
Intel Raptor Lake chip shown in a rendered image.

Engineering samples of the upcoming Intel Raptor Lake Core i7-13700K and Core i5-13600K processors have been thoroughly tested, and the results appeared on Bilibili, a Chinese social media platform.

Comparing the next-gen CPUs to their current-gen counterparts reveals massive performance gains, with some of the benchmarks returning up to 64% higher scores for Raptor Lake. Unfortunately, these performance gains come at a price.

Read more
Intel processors may get a lot more expensive, giving AMD an edge
A render of an Intel Core HX chip.

According to a new report, Intel might be about to introduce a substantial pricing increase on the majority of its catalog. Unfortunately, this also includes consumer-level processors. The company cites an increase in production and material cost as the reason why it decided to up its prices.

For the customers, it all comes down to one thing -- PC hardware and pre-built desktops and laptops might get a lot more expensive. The two key questions are: How much worse will the prices get, and how will Intel's competitors respond to this decision?

Read more
AMD and Intel duke it out in the GPD Win Max 2, and there’s a clear winner
A small GPD Win Max 2 laptop being held by two hands while playing a game with a Viking on the screen

GPD Win Max 2, the recently announced upcoming gaming console/handheld laptop hybrid, was just tested in a series of rather extensive benchmarks. Seeing as the GPD Win Max 2 comes in two variants, one with an AMD processor and one with Intel, both of them were compared to each other.

Sometimes, benchmark results can be inconclusive, but this time around, the winner is very clear to the point of it almost feeling unfair. AMD scored a resounding victory, but is there any hope for redemption for the Intel version of the console?

Read more