Insufficient access control vulnerability in subsystem for Intel(R) CSME prior to 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
intel converged security and management engine |
||
intel server platform services |
Although exploitation is like shooting a lone fish in a tiny barrel 1,000 miles away
A slit in Intel's security – a tiny window of opportunity – has been discovered, and it's claimed the momentary weakness could be one day exploited to wreak "utter chaos." It is a fascinating vulnerability, though non-trivial to abuse in a practical sense. It cannot be fixed without replacing the silicon, only mitigated, it is claimed: the design flaw is baked into millions of Intel processor chipsets manufactured over the past five years. The problem revolves around cryptographic keys that,...