Critical vulnerability in Intel processor firmware undiscovered for 10 years
In a Security Advisory, Intel warns of critical security gaps in the firmware of its own processors. The gap remained undiscovered for 10 years, but only affects business systems.

The error made it possible to bring the affected computers under the control of the attackers via their remote maintenance functions. A firmware update from Intel is required to close the gap, but this is not available for all affected systems. However, the vulnerability can only be exploited if one of the following technologies is set up and active on a system (this is disabled by default):
Affected are systems running Intel Manageability Firmware versions 6.x, 7.x, 8.x, 9.x, 10.x, 11.0, 11.5, and 11.6 for Intel Active Management Technology, Intel® Small Business Technology, and Intel Standard manageability work. Versions before 6 or after 11.6 are not affected.
Intel recommends using a detection guide (https://downloadcenter.intel.com/download/26755) to check if a system is affected by the firmware vulnerability. A check by the OEM of the system also provides information about the update status of the firmware: Versions in which the security gap has been closed have a four-digit build number beginning with 3, eg 8.1.71.3608.
If a firmware update is no longer possible for your system, we recommend disabling AMT, which can generally be done in the BIOS / UEFI settings of the computer concerned.
To the side...
Text sources & links
More information about the Intel vulnerability can be found here:
security-center.intel.com
Would you like to receive an offer?
Then inform us about your requirements, describe your ideas to us and one of our employees will carry out an initial consultation with you.
We will then present you with a rough concept and a non-binding, detailed cost offer.
Tel: 43 1 8698400
Email: office@iphos.com
Company
A strong international company - for the best IT solutions. Iphos IT Solutions offers its customers a full service in the areas of EDV / IT / ITSM, software development & web. – Faster, more cost-efficient & more competent.
IT infrastructure
As a holistic & sustainable service provider, we offer top IT solutions for maintenance, consulting, networks, Exchange, Linux & Windows servers and much more
Software Development
State-of-the-art software development from Vienna: as a sustainable & holistic IT company, we work on your best individual solution in the areas of application development, mobile software development, interface development & database development.
Web development
Web development rethought: We develop intranets & extranets, websites, e-commerce, online tariff calculators, newsletter systems & offer classic services such as SEO, SEM, etc. So that your business runs better.




