Categories: News

Major, ‘unfixable’ flaw detected in Intel processing chips

Security researchers claim to have found a massive security flaw in the present-day Intel chips.

The flaw is within the Converged Security and Management Engine (CSME) of the chip-set. The CSME controls the system boots, the power levels of the devices, the firmware, and the cryptographic functions. The flaw found can be used to break into the CSME, insert malicious code, and eventually, control all these functionalities.

A Security research firm known as Positive Technologies discovered the flaw and reported it last Thursday. This comes at a bad time for Intel as many flaws such as Meltdown and Spectre, and their successor, the ‘ZombieLoad’ were found recently, within the last three years.

The CSME is the first thing that turns on when your machine is booted up. It has its own processing unit, RAM, and ROM. Because it oversees the system’s firmware, one of the first thing it does is protect its own memory from malicious attacks and the likes. There is, however, a lag in the system and, for a brief period, the CSME is vulnerable and its data and memory remain unprotected. Hackers can launch a DMA transfer to the CSME’s memory in that time and take over the controls of the chip.

Security experts are deeming this flaw ‘unfixable’ and Intel’s integrity and reputation are being put on the line. Security researcher, Mark Ermolov has claimed that this “vulnerability jeopardizes everything Intel has done to build the root of trust and lay a solid security foundation on the company’s platforms.”

It has, however been mentioned that this flaw is extremely difficult to exploit. Hackers would, in most cases, need physical access to the device and the chip-set as well as additional specialized hardware equipment. Intel has spoken up about the flaw and have thus far told their users to keep their systems up to date with the newest software updates. They have also updated the security concerns and advisory page related to the CVE-2019-0090 on their website.

Sponsored
Taha Abdullah

Share
Published by
Taha Abdullah
Tags: Inteltop

Recent Posts

Samsung Partners with Sapphire Electronics for Local Production in Pakistan

Sapphire Electronics (Pvt) Limited, a wholly owned subsidiary of Reliance Cotton Spinning Mills Limited, has…

3 hours ago

Apple iPhone 16 Pro Max vs Google Pixel 9 Pro XL ; Key Insights You Need to Know

Apple and Google, two tech giants, have designed their latest offerings to meet the needs…

4 hours ago

What’s New in iOS 18.2.1? Here’s What You Should Know

iOS 18.2 introduces thrilling new features like Visual Intelligence, Image Playground, and upgraded writing tools.…

5 hours ago

Federal Govt Official Urges ‘Less’ Internet Use, Only for Important Matters

On Sunday, Syed Sajid Mehdi, Pakistan's Parliamentary Secretary for the Cabinet Division, proposed a solution…

5 hours ago

Federal Government Announces December 25 as Public Holiday

ISLAMABAD: The federal government has declared December 25, 2024, as a public holiday to mark…

5 hours ago

Samsung Terminates Employees Over Galaxy S25 Ultra Images Leak

An early setback occurred for Samsung's much anticipated Galaxy S25 series when unauthorized photographs of…

5 hours ago