Intel Active Management Technology£¨AMT£©·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-12·ì϶±àºÅºÍ¼¶±ð
CVE-2018-3628 ¸ß ³§ÉÌ×ÔÆÀ£º8.1 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-3629 ¸ß ³§ÉÌ×ÔÆÀ£º7.5 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-3632 ÖÐ ³§ÉÌ×ÔÆÀ£º6.4 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÔÚʹÓÃÓ¢ÌØ¶û´¦ÖÃÆ÷µÄPCÉ豸ÉÏÆôÓÃAMT¼¼Êõ£¬AMT¹Ì¼þ°æ±¾ÔÚ 3.xÖÁ11.x Ö®¼äµÄÎïÁªÍøÉ豸£¬¹¤×÷Õ¾£¬·þÎñÆ÷»áÊܵ½Ó°Ïì¡£
ÊÜÓ°ÏìCPUÐͺÅÈçÏ£º
?Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?ºÍÓ¢ÌØ¶û?Ѹ³Û?2²©Èñ?
?1ÖÁ8´úÓ¢ÌØ¶ûî£?´¦ÖÃÆ÷¼Ò×å
?Ó¢ÌØ¶û?ÖÁÇ¿?´¦ÖÃÆ÷E3-1200 v5ºÍv6²úƷϵÁУ¨Greenlow£©
?Ó¢ÌØ¶û?ÖÁÇ¿?´¦ÖÃÆ÷¿ÉÀ©´óϵÁУ¨Purley£©
?Ó¢ÌØ¶û?ÖÁÇ¿?´¦ÖÃÆ÷WϵÁУ¨Basin Falls£©
·ì϶¸ÅÊö
7ÔÂ10ÈÕ£¬Ó¢Ìضû¹«Ë¾¶ÔIntel Active Management Technology£¨intel AMT£©½øÐиüУ¬½¨²¹3¸ö²¹¶¡£¬±àºÅΪ£ºCVE-2018-3628£¬CVE-2018-3629£¬CVE-2018-3632¡£
Intel AMTÆäÈ«³ÆÎªIntel Active Management Technology(Ó¢ÌØ¶û×Ô¶¯ÖÎÀí¼¼Êõ)£¬ËüÊÇÒ»ÖÖ¼¯³ÉÔÚоƬÖеÄϵͳ£¬²»ÒÀÀµÌض¨µÄ²Ù×÷ϵͳ£¬ÕâÒ²ÊÇIntel AMTÓëÔ¶³Ì½ÚÔìÈí¼þ×î´óµÄ·ÖÆç¡£¼´±ãÍÆËã»úÊôÓڹعØ×´Ì¬£¬»òÕß²Ù×÷ϵͳ¹ÊÕÏ£¬Í¨¹ý´Ë¼¼Êõ¶¼Äܹ»½øÐÐÔ¶³ÌÖÎÀí¡£
CVE-2018-3628
ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄHttp´¦Ö÷¨Ê½ÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄHTTPÒªÇóÀ´ÌáÒé¹¥»÷£¬´Ó¶ø½ÚÔì¾ÖÓòÍøÖдæÔÚ·ì϶µÄ»úе£¬À´Ö´ÐжñÒâ´úÂë¡£
ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x
CVE-2018-3629
ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄEvent´¦Ö÷¨Ê½ÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâ´úÂëÀ´Ê¹Ö¸±ê»úÔì³É»Ø¾ø·þÎñ¡£
ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x
CVE-2018-3632
ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖÐÉϵÄAMTÄ£¿éÖдæÔÚÄÚ´æ·ÛËé·ì϶£¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâ´úÂëÀ´½øÐб¾µØ´úÂëÌáȨ¡£
ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º
6.x/7.x/8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20
½¨¸´½¨Ò飺
½¨ÒéÓû§¾¡¿ì¸üй̼þµ½×îа汾¡£
Ó¢ÌØ¶û°µÊ¾²»ÔÙÖ§³ÖÒÔϲúÆ·µÄÓ¢ÌØ¶û?CSME¹Ì¼þ¡£Ã»ÓжÔÒÔÏÂϵÁÐCPUÌṩ¹Ì¼þ¸üУº
Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?.
Ó¢ÌØ¶û?Ѹ³Û?2²©Èñ?.
µÚÒ»´úÓ¢ÌØ¶û?¿áî£?.
µÚ¶þ´úÓ¢ÌØ¶û?¿áî£?.
µÚÈý´úÓ¢ÌØ¶û?¿áî£?¡£
²Î¿¼Á´½Ó£º
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html


¾©¹«Íø°²±¸11010802024551ºÅ