Intel Active Management Technology£¨AMT£©·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-12

·ì϶±àºÅºÍ¼¶±ð

CVE-2018-3628  ¸ß  ³§ÉÌ×ÔÆÀ£º8.1  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE-2018-3629  ¸ß  ³§ÉÌ×ÔÆÀ£º7.5  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE-2018-3632  ÖÐ  ³§ÉÌ×ÔÆÀ£º6.4  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

Ó°ÏìÁìÓò

ÔÚʹÓÃÓ¢ÌØ¶û´¦ÖÃÆ÷µÄPCÉ豸ÉÏÆôÓÃAMT¼¼Êõ £¬AMT¹Ì¼þ°æ±¾ÔÚ 3.xÖÁ11.x Ö®¼äµÄÎïÁªÍøÉ豸 £¬¹¤×÷Õ¾ £¬·þÎñÆ÷»áÊܵ½Ó°Ïì¡£

ÊÜÓ°ÏìCPUÐͺÅÈçÏ£º

?Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?ºÍÓ¢ÌØ¶û?Ѹ³Û?2²©Èñ?

?1ÖÁ8´úÓ¢ÌØ¶ûî£?´¦ÖÃÆ÷¼Ò×å

?Ó¢ÌØ¶û?ÖÁÇ¿?´¦ÖÃÆ÷E3-1200 v5ºÍv6²úƷϵÁУ¨Greenlow£©

?Ó¢ÌØ¶û?ÖÁÇ¿?´¦ÖÃÆ÷¿ÉÀ©´óϵÁУ¨Purley£©

?Ó¢ÌØ¶û?ÖÁÇ¿?´¦ÖÃÆ÷WϵÁУ¨Basin Falls£©

·ì϶¸ÅÊö

7ÔÂ10ÈÕ £¬Ó¢Ìضû¹«Ë¾¶ÔIntel Active Management Technology£¨intel  AMT£©½øÐиüР£¬½¨²¹3¸ö²¹¶¡ £¬±àºÅΪ£ºCVE-2018-3628 £¬CVE-2018-3629 £¬CVE-2018-3632¡£

Intel AMTÆäÈ«³ÆÎªIntel Active Management Technology(Ó¢ÌØ¶û×Ô¶¯ÖÎÀí¼¼Êõ) £¬ËüÊÇÒ»ÖÖ¼¯³ÉÔÚоƬÖеÄϵͳ £¬²»ÒÀÀµÌض¨µÄ²Ù×÷ϵͳ £¬ÕâÒ²ÊÇIntel AMTÓëÔ¶³Ì½ÚÔìÈí¼þ×î´óµÄ·ÖÆç¡£¼´±ãÍÆËã»úÊôÓڹعØ×´Ì¬ £¬»òÕß²Ù×÷ϵͳ¹ÊÕÏ £¬Í¨¹ý´Ë¼¼Êõ¶¼Äܹ»½øÐÐÔ¶³ÌÖÎÀí¡£

CVE-2018-3628

ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄHttp´¦Ö÷¨Ê½ÖдæÔÚ»º³åÇøÒç¶Âí½Å £¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄHTTPÒªÇóÀ´ÌáÒé¹¥»÷ £¬´Ó¶ø½ÚÔì¾ÖÓòÍøÖдæÔÚ·ì϶µÄ»úе £¬À´Ö´ÐжñÒâ´úÂë¡£

ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x

CVE-2018-3629

ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄEvent´¦Ö÷¨Ê½ÖдæÔÚ»º³åÇøÒç¶Âí½Å £¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâ´úÂëÀ´Ê¹Ö¸±ê»úÔì³É»Ø¾ø·þÎñ¡£

ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x

CVE-2018-3632

ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖÐÉϵÄAMTÄ£¿éÖдæÔÚÄÚ´æ·ÛËé·ì϶ £¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâ´úÂëÀ´½øÐб¾µØ´úÂëÌáȨ¡£

ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º

6.x/7.x/8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20

 

½¨¸´½¨Ò飺

½¨ÒéÓû§¾¡¿ì¸üй̼þµ½×îа汾¡£

 


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

Ó¢ÌØ¶û°µÊ¾²»ÔÙÖ§³ÖÒÔϲúÆ·µÄÓ¢ÌØ¶û?CSME¹Ì¼þ¡£Ã»ÓжÔÒÔÏÂϵÁÐCPUÌṩ¹Ì¼þ¸üУº

Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?.

Ó¢ÌØ¶û?Ѹ³Û?2²©Èñ?.

µÚÒ»´úÓ¢ÌØ¶û?¿áî£?.

µÚ¶þ´úÓ¢ÌØ¶û?¿áî£?.

µÚÈý´úÓ¢ÌØ¶û?¿áî£?¡£

 

²Î¿¼Á´½Ó£º

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html