Intel CSMEÒýÇæ°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-14598£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.2£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Intel? CSME versions before 12.0.49 (IOT only: 12.0.56), 13.0.21, 14.0.11.
·ì϶¸ÅÊö
Intel Converged Security and Management Engine£¨CSME£¬¼´Èںϰ²È«ºÍ¿ÉÖÎÀíÐÔÒýÇæ£©ÊÇÍÆ¶¯ Intel »î¶¯ÖÎÀí¼¼ÊõµÄоƬ¼¯×Óϵͳ¡£CSMEÖ§³ÖÓ¢ÌØ¶ûµÄ×Ô¶¯ÖÎÀíϵͳӲ¼þºÍ¹Ì¼þ¼¼Êõ£¬¸Ã¼¼ÊõÓÃÓÚÏû·Ñ»ò¹«Ë¾PC£¬ÎïÁªÍø(IoT)É豸ºÍ¹¤×÷Õ¾ÖеÄÔ¶³Ì´ø±íÖÎÀí¡£
CSMEµÄ×Óϵͳ´æÔÚ²»ÕýÈ·µÄÉí·ÝÑéÖ¤ÃýÎó(CVE-2019-14598)£¬¸Ã·ì϶ÈçÔâÀûÓ㬿ɵ¼Ö±¾µØÍþвÐж¯Õß·¢ÆðÌáȨ¡¢»Ø¾ø·þÎñºÍÐÅϢй¶¹¥»÷¡£
Intel »¹°ä²¼ÁËÕë¶ÔWindows °æ±¾µÄ RAID Web Console 2 (RWC2) ºÍ RAID Web Console 3 (RWC3) µÄ°²È«¸üС£
µÚÒ»¸ö·ì϶ CVE-2020-0562 Ó°ÏìËùÓÐ RWC2 °æ±¾£¬CVSS ¸ù±¾·ÖΪ6.7£¬ÊôÓÚ¡°ÖÐΣ¡±·ì϶¡£±¾µØ¾ÈÏÖ¤µÄÓû§¿ÉÀûÓøÃȱµãÌáȨ£¬²»Íâ Intel ¹«Ë¾½«²»»á½¨¸´¸ÃÎÊÌ⣬¶øÊǰµÊ¾¸Ã²úÆ·½«Í£²ú£¬½¨ÒéÓû§¸üÐÂÖÁ RWC3°æ±¾¡£
µÚ¶þ¸ö·ì϶ CVE-2020-0564 »á²úÉúÒ»ÑùµÄDZÔÚºó¹û£¬ËüÓ°Ïì 7.010.009.000 °æ±¾Ö®Ç°µÄ RWC3 ²úÆ·¡£
Intel Manycore Platform Software Stack (MPSS) °æ±¾3.8.6 ֮ǰµÄ°æ±¾ÒÑÊÕµ½½¨¸´¹æ»®ÒÔ½â¾ö CVE-2020-0563¡£¸Ã·ì϶ΪÖÐΣ·ì϶£¬CVSS ¸ù±¾·ÖÊÇ6.7¡£Î´¾ÈÏÖ¤µÄÓû§ÄÜÀûÓø÷ì϶ͨ¹ýÒòȨÏÞ´¦Öò»ÕýÈ·¶øÔì³ÉµÄ±¾µØÈ¨ÏÞ¶øÒý·¢µÄÌáȨ¡£
Intel ¹«Ë¾»¹Ìáµ½ÁËÁí±íÒ»¸öÖÐΣ·ì϶ CVE-2020-0560£¬ËüÓ°Ïì Intel Renesas Electronics USB 3.0 Çý¶¯£¬¿Éµ¼ÖÂÔÚËùÓа汾ÖеÄÌáȨµÄºó¹û¡£Intel ¹«Ë¾°µÊ¾²»»á½¨¸´¸Ã·ì϶£¬¶øÊÇÍÆ¼öÓû§Ð¶ÔØ»òÖÕ³¡Ê¹ÓøòúÆ·¡£
Intel ¹«Ë¾»¹½¨¸´ÁËIntel SGX ÖеÄÒ»¸öµÍΣ·ì϶ CVE-2020-0561£¬ËüÊÇÒ»¸ö³õʼ»¯²»µ±ÎÊÌ⣬Æä CVSS ¸ù±¾·ÖΪ2.5·Ö£¬¿Éµ¼ÖÂÈÏÖ¤Óû§Í¨¹ý±¾µØ½Ó¼ûȨÏÞÌáȨ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html¡£
²Î¿¼Á´½Ó
https://www.zdnet.com/article/intel-warns-of-critical-security-flaw-in-csme-engine/


¾©¹«Íø°²±¸11010802024551ºÅ