Intel Management Engine Vulnerability Exposes Millions of PCs to Undetectable Attacks, Claims Security Firm

Advertisement
By Jamshed Avari | Updated: 10 November 2017 15:33 IST
Highlights
  • Intel's Management Engine is a microcontroller in PC motherboard chipsets
  • Intel recently switched to the embedded Minix operating system
  • It can be bridged to the USB subsystem allowing remote access

Security research firm Positive Technologies has said it will demonstrate an exploit that allows the running of arbitrary unsigned code on any PC with an Intel 6th Gen 'Skylake' Core CPU or later. The security hole exists because of Intel's Management Engine, a tiny microprocessor that exists within the platform controller, or chipset, of every PC motherboard built for Intel processors. The Intel Management Engine (IME) was introduced to allow functions such as remote booting and administration, but it also handles the initialisation of the CPU and its power management. It has long been suspected that the IME allows for undetectable backdoors that governments and other agencies can use to spy on users, but has been difficult to disable because of its deep low-level integration with the system.

Positive Technologies is set to reveal its findings at the annual Black Hat Europe conference for the IT security industry, which will begin on December 4 this year. According to the company, researchers have been able to introduce any code and execute it thanks to a design decision that connects the IME to a PC's USB subsystem to enable a debugging mechanism. It is already referring to the flaw as a "God-mode" hack because of its severity and scope.

Advertisement

Resesarchers have also been able to access the IME firmware, potentially allowing them to detect and exploit extremely low-level vulnerabilities.

The IME is completely transparent to PC users and their operating systems, operating on a much lower level. Users will have no way to detect that the IME has been compromised. Since the Skylake generation, Intel has been using the open-source Minix embedded operating system for IME functions, a decision that is partly responsible for the existence of this security hole.

Advertisement

Earlier this year, it was discovered that remote administration of the IME was possible without a password. This has since been rectified, but affected PCs need to have their motherboard firmware flashed in order to fix it, which most people are unlikely ever to do.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  2. Vivo T5x 5G Goes Official in India With 7,200mAh Battery
  3. Oppo K14 5G Debuts With 7,000mAh Battery at This Price in India
  4. Apple Reportedly Increases Foldable iPhone Panel Orders to 20 Million
  5. Best Mobiles Under Rs. 25,000 in India
  6. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  7. Samsung Could Equip Galaxy Z Fold 8, Wide Fold With These Batteries
  8. Oppo Watch X3 Goes Official With This Price Tag
  9. Samsung Galaxy Z TriFold Sales to Wind Down Just Three Months After Launch
  1. Instagram Rolls Out New AI Voice Effects For Voice Notes With Eight Filters
  2. Apple Reportedly Boosts Foldable Panel Orders to 20 Million, Suggesting Strong Demand for Foldable iPhone
  3. Smriti Irani Backs Women Entrepreneurs With SPARK Collective Push and British Council Partnership
  4. Oppo Watch X3 With Snapdragon W5 Chipset, Over 100 Sports Modes Launched
  5. Oppo Find N6 Launched With Snapdragon 8 Elite Gen 5 SoC, 6,000mAh Battery: Price, Features
  6. Poco X8 Pro Series Launched in India With Up to 9,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  7. OnePlus Pad 3 Tipped to Launch With 13.2-Inch Display, Snapdragon 8 Elite Gen 5 Chip
  8. Vivo X500 Series Chipsets Tipped Months Ahead of Launch; Vivo Pro Max Could Also Debut
  9. Argentina Bans Polymarket Over Unregulated Crypto Betting Concerns: Report
  10. Oura Ring 4 Launched in India With Smart Sensing Technology and HRV Tracking: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.