Researchers Find Unfixable Security Flaw in 5 Years of Intel Chips

Researchers have found a significant new safety flaw inside processors made by US multinational company and chip making big Intel for the previous 5 years. The flaw permit exploits to defeat hardware-based encryption and DRM protections. According to safety firm Positive Technologies, the safety bug might break aside a sequence of belief for essential expertise like silicon-based encryption, {hardware} authentication and trendy DRM protections.

“We will provide more technical details in a full-length white paper to be published soon. We should point out that when our specialists contacted Intel PSIRT to report the vulnerability, Intel said the company was already aware of it (CVE-2019-0090). Intel understands they cannot fix the vulnerability in the ROM of existing hardware. So they are trying to block all possible exploitation vectors. The patch for CVE-2019-0090 addresses only one potential attack vector, involving the Integrated Sensors Hub (ISH). We think there might be many ways to exploit this vulnerability in ROM. Some of them might require local access; others need physical access,” said Mark Ermolov, from Positive Technologies.

Virtually all Intel chips launched up to now 5 years comprise an unfixable flaw which will permit subtle attackers to defeat a bunch of safety measures constructed into the silicon.

Related Post

While Intel has issued patches to reduce the injury of exploits and make them more durable, safety agency Positive Technologies mentioned the mitigations might not be sufficient to totally defend methods, ArsTechnica reported on Friday.

The safety vulnerability found applies to machines with Intel chips constructed during the last 5 years or so. Intel mentioned that it was notified of the vulnerabilities and launched mitigations in May 2019 to be integrated into firmware updates for motherboards and pc methods.


Source link

This post was last modified on March 8, 2020 12:35 am

Joy: Hi Folks. I am Jyoti, pursuing my passion to write content on Technology and Automobiles. I am a B.Tech (IT) graduate who loves to write content on different niche. Being passionate since college days, I took it as my full-time career. I started this blog to deliver unbiased reviews to the readers and let them choose the right product based on their reviews. If you want to contact me, you can drop your mail at

This website uses cookies.