Intel CSMEÒýÇæ°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-14598£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.2£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Intel? CSME versions before 12.0.49 (IOT only: 12.0.56), 13.0.21, 14.0.11.
·ì϶¸ÅÊö
Intel Converged Security and Management Engine£¨CSME£¬£¬£¬£¬£¬£¬¼´Èںϰ²È«ºÍ¿ÉÖÎÀíÐÔÒýÇæ£©ÊÇÍÆ¶¯ Intel »î¶¯ÖÎÀí¼¼ÊõµÄоƬ¼¯×Óϵͳ¡£¡£¡£¡£¡£¡£CSMEÖ§³ÖÓ¢ÌØ¶ûµÄ×Ô¶¯ÖÎÀíϵͳӲ¼þºÍ¹Ì¼þ¼¼Êõ£¬£¬£¬£¬£¬£¬¸Ã¼¼ÊõÓÃÓÚÏû·Ñ»ò¹«Ë¾PC£¬£¬£¬£¬£¬£¬ÎïÁªÍø(IoT)É豸ºÍ¹¤×÷Õ¾ÖеÄÔ¶³Ì´ø±íÖÎÀí¡£¡£¡£¡£¡£¡£
CSMEµÄ×Óϵͳ´æÔÚ²»ÕýÈ·µÄÉí·ÝÑéÖ¤ÃýÎó(CVE-2019-14598)£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÈçÔâÀûÓ㬣¬£¬£¬£¬£¬¿Éµ¼Ö±¾µØÍþвÐж¯Õß·¢ÆðÌáȨ¡¢»Ø¾ø·þÎñºÍÐÅϢй¶¹¥»÷¡£¡£¡£¡£¡£¡£
Intel »¹°ä²¼ÁËÕë¶ÔWindows °æ±¾µÄ RAID Web Console 2 (RWC2) ºÍ RAID Web Console 3 (RWC3) µÄ°²È«¸üС£¡£¡£¡£¡£¡£
µÚÒ»¸ö·ì϶ CVE-2020-0562 Ó°ÏìËùÓÐ RWC2 °æ±¾£¬£¬£¬£¬£¬£¬CVSS ¸ù±¾·ÖΪ6.7£¬£¬£¬£¬£¬£¬ÊôÓÚ¡°ÖÐΣ¡±·ì϶¡£¡£¡£¡£¡£¡£±¾µØ¾ÈÏÖ¤µÄÓû§¿ÉÀûÓøÃȱµãÌáȨ£¬£¬£¬£¬£¬£¬²»Íâ Intel ¹«Ë¾½«²»»á½¨¸´¸ÃÎÊÌ⣬£¬£¬£¬£¬£¬¶øÊǰµÊ¾¸Ã²úÆ·½«Í£²ú£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ RWC3°æ±¾¡£¡£¡£¡£¡£¡£
µÚ¶þ¸ö·ì϶ CVE-2020-0564 »á²úÉúÒ»ÑùµÄDZÔÚºó¹û£¬£¬£¬£¬£¬£¬ËüÓ°Ïì 7.010.009.000 °æ±¾Ö®Ç°µÄ RWC3 ²úÆ·¡£¡£¡£¡£¡£¡£
Intel Manycore Platform Software Stack (MPSS) °æ±¾3.8.6 ֮ǰµÄ°æ±¾ÒÑÊÕµ½½¨¸´¹æ»®ÒÔ½â¾ö CVE-2020-0563¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪÖÐΣ·ì϶£¬£¬£¬£¬£¬£¬CVSS ¸ù±¾·ÖÊÇ6.7¡£¡£¡£¡£¡£¡£Î´¾ÈÏÖ¤µÄÓû§ÄÜÀûÓø÷ì϶ͨ¹ýÒòȨÏÞ´¦Öò»ÕýÈ·¶øÔì³ÉµÄ±¾µØÈ¨ÏÞ¶øÒý·¢µÄÌáȨ¡£¡£¡£¡£¡£¡£
Intel ¹«Ë¾»¹Ìáµ½ÁËÁí±íÒ»¸öÖÐΣ·ì϶ CVE-2020-0560£¬£¬£¬£¬£¬£¬ËüÓ°Ïì Intel Renesas Electronics USB 3.0 Çý¶¯£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔÚËùÓа汾ÖеÄÌáȨµÄºó¹û¡£¡£¡£¡£¡£¡£Intel ¹«Ë¾°µÊ¾²»»á½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬£¬¶øÊÇÍÆ¼öÓû§Ð¶ÔØ»òÖÕ³¡Ê¹ÓøòúÆ·¡£¡£¡£¡£¡£¡£
Intel ¹«Ë¾»¹½¨¸´ÁËIntel SGX ÖеÄÒ»¸öµÍΣ·ì϶ CVE-2020-0561£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸ö³õʼ»¯²»µ±ÎÊÌ⣬£¬£¬£¬£¬£¬Æä CVSS ¸ù±¾·ÖΪ2.5·Ö£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÈÏÖ¤Óû§Í¨¹ý±¾µØ½Ó¼ûȨÏÞÌáȨ¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zdnet.com/article/intel-warns-of-critical-security-flaw-in-csme-engine/


¾©¹«Íø°²±¸11010802024551ºÅ