Intel CSMEÒýÇæÇå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-14Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-14598£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.2£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Intel? CSME versions before 12.0.49 (IOT only: 12.0.56), 13.0.21, 14.0.11.
Îó²î¸ÅÊö
Intel Converged Security and Management Engine£¨CSME£¬£¬£¬£¬£¬£¬¼´ÈÚºÏÇå¾²ºÍ¿ÉÖÎÀíÐÔÒýÇæ£©ÊÇÍÆ¶¯ Intel »î¶¯ÖÎÀíÊÖÒÕµÄоƬ¼¯×Óϵͳ¡£¡£¡£¡£¡£¡£CSMEÖ§³ÖÓ¢ÌØ¶ûµÄ×Ô¶¯ÖÎÀíϵͳӲ¼þºÍ¹Ì¼þÊÖÒÕ£¬£¬£¬£¬£¬£¬¸ÃÊÖÒÕÓÃÓÚÏûºÄ»ò¹«Ë¾PC£¬£¬£¬£¬£¬£¬ÎïÁªÍø(IoT)×°±¸ºÍÊÂÇéÕ¾ÖеÄÔ¶³Ì´øÍâÖÎÀí¡£¡£¡£¡£¡£¡£
CSMEµÄ×Óϵͳ±£´æ²»×¼È·µÄÉí·ÝÑéÖ¤¹ýʧ(CVE-2019-14598)£¬£¬£¬£¬£¬£¬¸ÃÎó²îÈçÔâʹÓ㬣¬£¬£¬£¬£¬¿Éµ¼ÖÂÍâµØÍþвÐж¯Õß·¢¶¯ÌáȨ¡¢¾Ü¾øÐ§ÀͺÍÐÅϢй¶¹¥»÷¡£¡£¡£¡£¡£¡£
Intel »¹Ðû²¼ÁËÕë¶ÔWindows °æ±¾µÄ RAID Web Console 2 (RWC2) ºÍ RAID Web Console 3 (RWC3) µÄÇå¾²¸üС£¡£¡£¡£¡£¡£
µÚÒ»¸öÎó²î CVE-2020-0562 Ó°ÏìËùÓÐ RWC2 °æ±¾£¬£¬£¬£¬£¬£¬CVSS »ùÌìְΪ6.7£¬£¬£¬£¬£¬£¬ÊôÓÚ¡°ÖÐΣ¡±Îó²î¡£¡£¡£¡£¡£¡£ÍâµØ¾ÈÏÖ¤µÄÓû§¿ÉʹÓøÃȱÏÝÌáȨ£¬£¬£¬£¬£¬£¬²»¹ý Intel ¹«Ë¾½«²»»áÐÞ¸´¸ÃÎÊÌ⣬£¬£¬£¬£¬£¬¶øÊÇÌåÏָòúÆ·½«Í£²ú£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ RWC3°æ±¾¡£¡£¡£¡£¡£¡£
µÚ¶þ¸öÎó²î CVE-2020-0564 »á±¬·¢ÏàͬµÄDZÔÚЧ¹û£¬£¬£¬£¬£¬£¬ËüÓ°Ïì 7.010.009.000 °æ±¾Ö®Ç°µÄ RWC3 ²úÆ·¡£¡£¡£¡£¡£¡£
Intel Manycore Platform Software Stack (MPSS) °æ±¾3.8.6 ֮ǰµÄ°æ±¾ÒÑÊÕµ½ÐÞ¸´¼Æ»®ÒÔ½â¾ö CVE-2020-0563¡£¡£¡£¡£¡£¡£¸ÃÎó²îΪÖÐΣÎó²î£¬£¬£¬£¬£¬£¬CVSS »ùÌìÖ°ÊÇ6.7¡£¡£¡£¡£¡£¡£Î´¾ÈÏÖ¤µÄÓû§ÄÜʹÓøÃÎó²îͨ¹ýÒòȨÏÞ´¦Öóͷ£²»×¼È·¶øÔì³ÉµÄÍâµØÈ¨ÏÞ¶øÒý·¢µÄÌáȨ¡£¡£¡£¡£¡£¡£
Intel ¹«Ë¾»¹Ìáµ½ÁËÁíÍâÒ»ÆäÖÐΣÎó²î CVE-2020-0560£¬£¬£¬£¬£¬£¬ËüÓ°Ïì Intel Renesas Electronics USB 3.0 Çý¶¯£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔÚËùÓа汾ÖеÄÌáȨµÄЧ¹û¡£¡£¡£¡£¡£¡£Intel ¹«Ë¾ÌåÏÖ²»»áÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬¶øÊÇÍÆ¼öÓû§Ð¶ÔØ»ò×èֹʹÓøòúÆ·¡£¡£¡£¡£¡£¡£
Intel ¹«Ë¾»¹ÐÞ¸´ÁËIntel SGX ÖеÄÒ»¸öµÍΣÎó²î CVE-2020-0561£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸ö³õʼ»¯²»µ±ÎÊÌ⣬£¬£¬£¬£¬£¬Æä CVSS »ùÌìְΪ2.5·Ö£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÈÏÖ¤Óû§Í¨¹ýÍâµØ»á¼ûȨÏÞÌáȨ¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zdnet.com/article/intel-warns-of-critical-security-flaw-in-csme-engine/


¾©¹«Íø°²±¸11010802024551ºÅ