Intel CSMEÒýÇæ°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-14

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14598£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.2£¬ £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Intel? CSME versions before 12.0.49 (IOT only: 12.0.56), 13.0.21, 14.0.11.


·ì϶¸ÅÊö


Intel Converged Security and Management Engine£¨CSME£¬ £¬£¬£¬£¬£¬¼´Èںϰ²È«ºÍ¿ÉÖÎÀíÐÔÒýÇæ£©ÊÇÍÆ¶¯ Intel »î¶¯ÖÎÀí¼¼ÊõµÄоƬ¼¯×Óϵͳ¡£¡£¡£¡£¡£¡£CSMEÖ§³ÖÓ¢ÌØ¶ûµÄ×Ô¶¯ÖÎÀíϵͳӲ¼þºÍ¹Ì¼þ¼¼Êõ£¬ £¬£¬£¬£¬£¬¸Ã¼¼ÊõÓÃÓÚÏû·Ñ»ò¹«Ë¾PC£¬ £¬£¬£¬£¬£¬ÎïÁªÍø(IoT)É豸ºÍ¹¤×÷Õ¾ÖеÄÔ¶³Ì´ø±íÖÎÀí¡£¡£¡£¡£¡£¡£


CSMEµÄ×Óϵͳ´æÔÚ²»ÕýÈ·µÄÉí·ÝÑéÖ¤ÃýÎó(CVE-2019-14598)£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÈçÔâÀûÓ㬠£¬£¬£¬£¬£¬¿Éµ¼Ö±¾µØÍþвÐж¯Õß·¢ÆðÌáȨ¡¢»Ø¾ø·þÎñºÍÐÅϢй¶¹¥»÷¡£¡£¡£¡£¡£¡£


Intel »¹°ä²¼ÁËÕë¶ÔWindows °æ±¾µÄ RAID Web Console 2 (RWC2) ºÍ RAID Web Console 3 (RWC3) µÄ°²È«¸üС£¡£¡£¡£¡£¡£


µÚÒ»¸ö·ì϶ CVE-2020-0562 Ó°ÏìËùÓÐ RWC2 °æ±¾£¬ £¬£¬£¬£¬£¬CVSS ¸ù±¾·ÖΪ6.7£¬ £¬£¬£¬£¬£¬ÊôÓÚ¡°ÖÐΣ¡±·ì϶¡£¡£¡£¡£¡£¡£±¾µØ¾­ÈÏÖ¤µÄÓû§¿ÉÀûÓøÃȱµãÌáȨ£¬ £¬£¬£¬£¬£¬²»Íâ Intel ¹«Ë¾½«²»»á½¨¸´¸ÃÎÊÌ⣬ £¬£¬£¬£¬£¬¶øÊǰµÊ¾¸Ã²úÆ·½«Í£²ú£¬ £¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ RWC3°æ±¾¡£¡£¡£¡£¡£¡£


µÚ¶þ¸ö·ì϶ CVE-2020-0564 »á²úÉúÒ»ÑùµÄDZÔÚºó¹û£¬ £¬£¬£¬£¬£¬ËüÓ°Ïì 7.010.009.000 °æ±¾Ö®Ç°µÄ RWC3 ²úÆ·¡£¡£¡£¡£¡£¡£


Intel Manycore Platform Software Stack (MPSS) °æ±¾3.8.6 ֮ǰµÄ°æ±¾ÒÑÊÕµ½½¨¸´¹æ»®ÒÔ½â¾ö CVE-2020-0563¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪÖÐΣ·ì϶£¬ £¬£¬£¬£¬£¬CVSS ¸ù±¾·ÖÊÇ6.7¡£¡£¡£¡£¡£¡£Î´¾­ÈÏÖ¤µÄÓû§ÄÜÀûÓø÷ì϶ͨ¹ýÒòȨÏÞ´¦Öò»ÕýÈ·¶øÔì³ÉµÄ±¾µØÈ¨ÏÞ¶øÒý·¢µÄÌáȨ¡£¡£¡£¡£¡£¡£


Intel ¹«Ë¾»¹Ìáµ½ÁËÁí±íÒ»¸öÖÐΣ·ì϶ CVE-2020-0560£¬ £¬£¬£¬£¬£¬ËüÓ°Ïì Intel Renesas Electronics USB 3.0 Çý¶¯£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂÔÚËùÓа汾ÖеÄÌáȨµÄºó¹û¡£¡£¡£¡£¡£¡£Intel ¹«Ë¾°µÊ¾²»»á½¨¸´¸Ã·ì϶£¬ £¬£¬£¬£¬£¬¶øÊÇÍÆ¼öÓû§Ð¶ÔØ»òÖÕ³¡Ê¹ÓøòúÆ·¡£¡£¡£¡£¡£¡£


Intel ¹«Ë¾»¹½¨¸´ÁËIntel SGX ÖеÄÒ»¸öµÍΣ·ì϶ CVE-2020-0561£¬ £¬£¬£¬£¬£¬ËüÊÇÒ»¸ö³õʼ»¯²»µ±ÎÊÌ⣬ £¬£¬£¬£¬£¬Æä CVSS ¸ù±¾·ÖΪ2.5·Ö£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂÈÏÖ¤Óû§Í¨¹ý±¾µØ½Ó¼ûȨÏÞÌáȨ¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ £¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/intel-warns-of-critical-security-flaw-in-csme-engine/