Latest Intel CPUs have 'impossible to fix' security flaw

(Image credit: Intel)

New warnings claim that pretty much every Intel processor released in the last five years has a security flaw baked into the silicon which can’t actually be fixed as such, although the chip maker has already implemented mitigations.

Security firm Positive Technologies found that Intel’s mitigations (enacted since the initial bug was first discovered in May 2019) might not be sufficient to fully protect a PC from an attack.

The more positive news (pun not intended) is that the vulnerability, which is present in Intel’s Converged Security and Management Engine (CSME) – a subsystem inside the CPU which takes care of all manner of important security duties, right from pushing the power button – is not trivial to exploit. In fact it’s a tricky matter to do so.

Intel first described the security flaw as: “Insufficient access control vulnerability in subsystem for [CSME versions] … may allow an unauthenticated user to potentially enable escalation of privilege via physical access.”

So in other words, you need physical access (or local access, potentially in some cases, Positive Technologies qualifies) to the machine to attempt to leverage the vulnerability, which coupled with the sophisticated nature of the attack, makes this a difficult exploit to pull off.

But it’s still a worrying state of affairs when there’s apparently a security flaw directly in the silicon which isn’t fixable, as it can’t be patched via a firmware update.

Positive Technologies observes that this is because the problem is present in the “very early stages of the subsystem’s [CSME’s] operation, in its boot ROM”, and that it’s “impossible to fix firmware errors that are hard-coded in the mask ROM.”

Chain of trust

The security firm further notes that Intel has said it’s already aware of the issues here, and understands that it cannot fix the vulnerability in the ROM, so instead it’s attempting to patch all possible attack vectors. But mitigating against every conceivable exploit could obviously be a difficult process.

Positive Technologies warned: “This vulnerability jeopardizes everything Intel has done to build the root of trust and lay a solid security foundation on the company’s platforms … The larger worry is that, because this vulnerability allows a compromise at the hardware level, it destroys the chain of trust for the platform as a whole.”

In short, it’s another blow to Intel’s reputation on the security front, which it can ill afford given the huge amount of ground AMD is gaining with its Ryzen offerings.

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Read more
Security
Intel slams Nvidia and AMD, claims chip giants have huge numbers of security flaws
AMD logo
AMD patches high severity security flaw affecting Zen chips
AMD Ryzen 5 7600X processor
AMD confirms processor security flaws after Asus patch slips out early
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
AMD VM security tools can be bypassed, letting hackers infilitrate your devices, experts warn
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
The socket interface of the Intel Core Ultra processor
Got an Intel Core Ultra 200S CPU? These are the patches you need to help gaming performance – with one more update coming in January 2025
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price