Intel CSMEÒýÇæ°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-14

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14598 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.2 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Intel? CSME versions before 12.0.49 (IOT only: 12.0.56), 13.0.21, 14.0.11.


·ì϶¸ÅÊö


Intel Converged Security and Management Engine£¨CSME £¬¼´Èںϰ²È«ºÍ¿ÉÖÎÀíÐÔÒýÇæ£©ÊÇÍÆ¶¯ Intel »î¶¯ÖÎÀí¼¼ÊõµÄоƬ¼¯×Óϵͳ¡£CSMEÖ§³ÖÓ¢ÌØ¶ûµÄ×Ô¶¯ÖÎÀíϵͳӲ¼þºÍ¹Ì¼þ¼¼Êõ £¬¸Ã¼¼ÊõÓÃÓÚÏû·Ñ»ò¹«Ë¾PC £¬ÎïÁªÍø(IoT)É豸ºÍ¹¤×÷Õ¾ÖеÄÔ¶³Ì´ø±íÖÎÀí¡£


CSMEµÄ×Óϵͳ´æÔÚ²»ÕýÈ·µÄÉí·ÝÑéÖ¤ÃýÎó(CVE-2019-14598) £¬¸Ã·ì϶ÈçÔâÀûÓà £¬¿Éµ¼Ö±¾µØÍþвÐж¯Õß·¢ÆðÌáȨ¡¢»Ø¾ø·þÎñºÍÐÅϢй¶¹¥»÷¡£


Intel »¹°ä²¼ÁËÕë¶ÔWindows °æ±¾µÄ RAID Web Console 2 (RWC2) ºÍ RAID Web Console 3 (RWC3) µÄ°²È«¸üС£


µÚÒ»¸ö·ì϶ CVE-2020-0562 Ó°ÏìËùÓÐ RWC2 °æ±¾ £¬CVSS ¸ù±¾·ÖΪ6.7 £¬ÊôÓÚ¡°ÖÐΣ¡±·ì϶¡£±¾µØ¾­ÈÏÖ¤µÄÓû§¿ÉÀûÓøÃȱµãÌáȨ £¬²»Íâ Intel ¹«Ë¾½«²»»á½¨¸´¸ÃÎÊÌâ £¬¶øÊǰµÊ¾¸Ã²úÆ·½«Í£²ú £¬½¨ÒéÓû§¸üÐÂÖÁ RWC3°æ±¾¡£


µÚ¶þ¸ö·ì϶ CVE-2020-0564 »á²úÉúÒ»ÑùµÄDZÔÚºó¹û £¬ËüÓ°Ïì 7.010.009.000 °æ±¾Ö®Ç°µÄ RWC3 ²úÆ·¡£


Intel Manycore Platform Software Stack (MPSS) °æ±¾3.8.6 ֮ǰµÄ°æ±¾ÒÑÊÕµ½½¨¸´¹æ»®ÒÔ½â¾ö CVE-2020-0563¡£¸Ã·ì϶ΪÖÐΣ·ì϶ £¬CVSS ¸ù±¾·ÖÊÇ6.7¡£Î´¾­ÈÏÖ¤µÄÓû§ÄÜÀûÓø÷ì϶ͨ¹ýÒòȨÏÞ´¦Öò»ÕýÈ·¶øÔì³ÉµÄ±¾µØÈ¨ÏÞ¶øÒý·¢µÄÌáȨ¡£


Intel ¹«Ë¾»¹Ìáµ½ÁËÁí±íÒ»¸öÖÐΣ·ì϶ CVE-2020-0560 £¬ËüÓ°Ïì Intel Renesas Electronics USB 3.0 Çý¶¯ £¬¿Éµ¼ÖÂÔÚËùÓа汾ÖеÄÌáȨµÄºó¹û¡£Intel ¹«Ë¾°µÊ¾²»»á½¨¸´¸Ã·ì϶ £¬¶øÊÇÍÆ¼öÓû§Ð¶ÔØ»òÖÕ³¡Ê¹ÓøòúÆ·¡£


Intel ¹«Ë¾»¹½¨¸´ÁËIntel SGX ÖеÄÒ»¸öµÍΣ·ì϶ CVE-2020-0561 £¬ËüÊÇÒ»¸ö³õʼ»¯²»µ±ÎÊÌâ £¬Æä CVSS ¸ù±¾·ÖΪ2.5·Ö £¬¿Éµ¼ÖÂÈÏÖ¤Óû§Í¨¹ý±¾µØ½Ó¼ûȨÏÞÌáȨ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/intel-warns-of-critical-security-flaw-in-csme-engine/