HomeSecurityIntel fixes flaws that allow hackers to run arbitrary code

Intel fixes flaws that allow hackers to run arbitrary code

IntelIntel releases new patches .

A blog post by Positive Technologies has analyzed four different vulnerabilities found in the Intel Management Engine. Patches for these flaws were released in early July.

It is worth noting that the flaws found are similar to those reported by the security firm last year. These huge flaws gave attackers a fair level of access to processes running on the device.

Similarly, the newer flaws could allow an attacker to execute arbitrary code in the Active Management Technology environment – ​​without requiring admin access for the AMT account.

Speaking specifically about the vulnerabilities, the first one is CVE-2018-3627. Dubbed a logic bug, this easily exploitable flaw allows code execution. CVE-2018-3628 is its more dangerous sibling, allowing extensive remote code execution in the AMT process. It is also known as “Buffer overflow in HTTP handler”.

The other two bugs are CVE-2018-3629 and CVE-2018-3632, which is a memory leak. You can read more about these bugs in the blog post.

As for the processors that will benefit from the patches released by Intel, those are not Intel's 1st, 2nd, and 3rd generation processors, which will remain unpatched, according to The Register. This is because Intel no longer supports these older CPUs.

Various OEMs (Original equipment manufacturers) have already started releasing patches and it might be a good idea to contact your computer manufacturer about this issue.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS