HomeSecurityIntel: Security flaw identified in the company's CSME!

Intel: Security flaw identified in the company's CSME!

IntelIntel is reporting a critical flaw in CSME and is urging users to apply a patch, which is now available, as soon as possible. The Intel Converged Security and Management Engine (CSME) is a chipset subsystem that powers Intel's Active Management technologies. A flaw in the CSME firmware has been identified by Intel's security team. If exploited, this flaw could allow attackers to launch privilege escalation, denial of service, and information disclosure attacks. The flaw, identified as CVE-2019-14598, has a CVSS base score of 8.2, which is the highest severity rating. Therefore, the flaw is rated critical.

Intel released a firmware update to mitigate the flaw affecting CSME versions prior to 12.0.49 (including only the IOT: 12.0.56), 13.0.21 and 14.0.11.

Also Intel recommends updating to CSME versions 12.0.49, 13.0.21 and 14.0.11 or newer from the system manufacturer that is experiencing these issues. It also advises IOT customers to use CSME version 12.0.55 to update to 12.0.56 or a newer version provided by the system manufacturer that is facing these problems.

Another series of updates aims to resolve security issues found in Intel's RAID Web Console 2 (RWC2) and the Web RAID Console 3 (RWC3) for Windows.

The first vulnerability, CVE-2020-0562, impacts all versions of the RWC2 and has received a severity rating of 6.7, classifying the flaw as medium severity. Local privileged users can exploit the vulnerability to elevate their privileges.

However, Intel has no plans to fix the issue. Instead, it says the product will be discontinued and recommends users upgrade to RWC3.

The second security flaw is the same with the same potential consequences. It is identified as CVE-2020-0564 and affects RWC3 before version 7,010,009,000. Intel's Multicore Platform Stack (MPSS) before version 3.8.6 also received a fix to fix CVE-2020-0563, which was rated medium with a severity rating of 6.7. This flaw can be exploited by hackers to enable privilege escalation via local access due to mismanagement of privileges.
Intel has reported another medium severity security flaw identified as CVE-2020-0560 , and is not prepared to release a patch. This flaw affects the Intel Renesas Electronics USB 3.0 driver and allows privilege escalation across all versions. Thus, it suggests that users of the Intel Electronics Renesas Electronics USB 3.0 driver uninstall it or discontinue use at the first opportunity.

Additionally, Intel has patched a low-severity bug in Intel's software extensions (SGX). This bug, identified as CVE-2020-0561 and rated 2.5, could allow authenticated users to elevate their privileges via local access.

Meanwhile, Microsoft also released the monthly security patch bundle, and the February set fixed a total of 99 bugs, of which 11 were rated critical.Microsoft-Adobe

Software including Internet Explorer, Edge browser, Microsoft Exchange Server and Microsoft Office are included in the update.
Adobe patched several bugs in software including Acrobat and Reader, Flash and Adobe Experience Manager.

Finally, Microsoft released Intel updates for Windows 10 versions 1909 and 1903 to help Intel distribute firmware that is protected from exploits.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS