Intel VISA Exploit Gives Access to Computer’s Entire Data, Researchers Show

Advertisement
By Gaurav Shukla | Updated: 29 March 2019 18:28 IST
Highlights
  • Researchers used previously disclosed vulnerabilities to access VISA
  • Intel is very secretive about VISA and information about it is not public
  • Intel underplayed the VISA exploits

Intel VISA is said to be a utility that is bundled by the chipmaker for testing

Security researchers have discovered a previously unknown feature in the Intel chipsets, which could allow an attacker to intercept data from the computer memory. The feature called Intel Visualization of Internal Signals Architecture (Intel VISA) is said to be a utility that is bundled by the chipmaker for testing on the manufacturing lines. Although Intel doesn't publicly disclose the existence of Intel VISA and is extremely secretive about it, the researchers were able to find several ways to enable the feature on the Intel chipsets and capture the data from the CPU.

As a per presentation made by the researchers Mark Ermolov and Maxim Goryachy of Positive Technologies at the ongoing Blackhat Asia 2019 conference in Singapore, their exploits of the Intel chipsets don't require any hardware modifications or special equipment. One of the techniques shared by the researchers involved vulnerabilities detailed in Intel-SA-00086 advisory that give access to Intel Management Engine (Intel ME), in turn helping enable VISA. Access to Intel VISA makes the computer's entire data vulnerable and obtainable for the attacker.

Advertisement

Intel underplayed the exploit and told ZDNet that the VISA issue requires physical access to the machines and the Intel-SA-00086 vulnerabilities have already been mitigated. The researchers however disagreed with Intel's comments and reportedly said in an online discussion that the patched Intel firmware can be downgraded using Intel ME, making the chipset vulnerable and opening the door for accessing Intel VISA.

Mark Ermolov also noted that the vulnerabilities detailed in Intel-SA-00086 are just one of the ways to access VISA, and there are other methods as well, including Orange Mystery and Intel JTAG password. The technical details of these exploits can be found in the presentation slides shared on Blackhat Asia website.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Note 17 Appears on Certification Website Ahead of Anticipated Debut
  2. WWDC 2026: iOS 27, iPadOS 27 Won't Be Compatible With These Devices
  3. iOS 27 Release Date and How to Update: Supported iPhones
  4. Here Are Apple's Top Announcements From Its Annual Developer Conference
  5. Apple Unveils iOS 27 With Revamped Siri and Liquid Glass Improvements
  6. Oppo Reno 16 Indian Variant Surfaces on Benchmarking Site Ahead of Debut
  7. Samsung Galaxy Z Fold 8 Ultra Listed on BIS Database, May Launch Soon
  8. OnePlus 15 Reportedly Gains AirDrop Support Through Quick Share
  1. James Webb Space Telescope Weighs Most Distant Dormant Black Hole Ever Detected
  2. Stellar Blade: Blood Rain Protagonist Will Have More of a Personality, Says Shift Up
  3. Samsung Galaxy Tab Active 6 Reportedly Set to Launch in 2027 With 5G Connectivity
  4. iOS 27 Finally Adds Separate Volume Controls for Ringtones and Alarms, Just Like Android Phones
  5. UK Regulator Proposes Allowing Retail Funds to Hold Up to 10 Percent in Crypto ETNs
  6. Samsung Galaxy Z Fold 8 Ultra Reportedly Listed on BIS Database, Tipster Leaks Key Specifications
  7. Redmi Note 17 Visits EEC Certification Database Along With a New Vivo Handset, Hinting at Imminent Global Launch
  8. OnePlus 15 Gains AirDrop Support via Quick Share as Google Expands Availability Beyond Pixel, Samsung Phones
  9. Apple Will Soon Allow Android, Windows Users to Share Photos to iCloud Shared Albums
  10. WhatsApp Claims NSO Group-Linked Entity Unsuccessfully Carried Out Fresh Phishing Attacks Against Users
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.