Intel x86 processor design error open to rootkits

Intel's

Intel processors from the late 90s reportedly have a hidden flaw that allows rootkits to be installed by malicious actors.

A security researcher has claimed that a design flaw in the x86 processor from 1997 has lain undiscovered until now and would allow attackers to implement a root kit in the low-level firmware that is virtually undetectable by security products, reports PC World.

The feature added to the x86 architecture in 1997 was disclosed at the Black Hat security conference by Christopher Domas from the Battelle Memorial Institute. Domas revealed that the toolkit can be successfully installed in the System Management Mode (SMM).

Once an attacker has done that, the flaw can be used to delete the UEFI (Unified Extensible Firmware Interface), the BIOS or reinfect the OS following a clean install. Domas goes on to add that starting up in Secure Boot mode won't help one jot as that relies on the SMM to run correctly.

AMD as well?

Before panic sets in, be advised that attackers need to have kernel or system privileges on the computer in question to be able to exploit the flaw. Domas also went on to claim that x86 processors made by AMD may even be affected, however, no testing has been done to indicate that as being the case.

To prevent the flaw being exploited, Intel is rolling out firmware updates for older processors and has mitigated against the issue in its latest CPUs, however, Domas claimed that not all of the older processors can even be patched.

TOPICS
Latest in Pro
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand