Ó¢ÌØ¶ûCSME·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-12

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-3655 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.3 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


·ì϶ӰÏìÓ¢ÌØ¶ûCSME¹Ì¼þ°æ±¾£º11.0ÖÁ11.8.50 £¬ 11.10ÖÁ11.11.50 £¬ 11.20ÖÁ11.21.51¡£
Ó¢ÌØ¶û·þÎñÆ÷ƽ̨·þÎñ¹Ì¼þ°æ±¾£º4.0£¨½öÏÞPurleyºÍBakerville£©¡£

Ó¢ÌØ¶ûTXE°æ±¾£º3.0µ½3.1.50¡£


·ì϶¸ÅÊö


·ì϶´æÔÚÓÚ11.21.55°æ±¾Ö®Ç°µÄÓ¢ÌØ¶ûCSMEÖеÄ×Óϵͳ £¬4.0°æ±¾Ö®Ç°µÄÓ¢ÌØ¶û·þÎñÆ÷ƽ̨·þÎñºÍ3.1.55°æ±¾Ö®Ç°µÄÓ¢ÌØ¶û¿ÉÐÅÖ´ÐÐÒýÇæ¹Ì¼þÖÐ £¬¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§Í¨¹ýÎïÀí½Ó¼ûÀ´Åú¸Ä»òй©ÐÅÏ¢¡£


ÓµÓÐÎïÀí½Ó¼ûȨÏÞµÄδ¾­Éí·ÝÑéÖ¤µÄÓû§Äܹ»£ºÈƹýÓ¢ÌØ¶ûCSME ·´³Á·Å± £»¤ £¬¿ÉÄÜÔÊÐí±©Á¦¹¥»÷À´»ñÈ¡´æ´¢ÔÚÓ¢ÌØ¶ûCSMEÄÚµÄÐÅÏ¢¡ £»ñµÃδ¾­ÊÚȨ½Ó¼ûÓ¢ÌØ¶ûMEBXµÄÃÜÂë¡£´Û¸ÄÓ¢ÌØ¶ûCSMEÎļþϵͳĿ¼µÄÆëÈ«ÐÔ»ò·þÎñÆ÷ƽ̨·þÎñºÍ¿ÉÐÅÖ´Ðл·¾³£¨Ó¢ÌضûTXT£©Êý¾ÝÎļþ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC\EXP


½¨¸´½¨Òé


ÇëÓ¢ÌØ¶ûCSME £¬Ó¢Ìضû·þÎñÆ÷ƽ̨·þÎñºÍÓ¢ÌØ¶û¿ÉÐÅÖ´ÐÐÒýÇæ£¨TXE£©µÄÓû§¸üÐÂ×îв¹¶¡¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00125.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00086.html