Windows 10: Intel chip vulnerability lets hackers easily hijack fleets of PCs

Discus and support Intel chip vulnerability lets hackers easily hijack fleets of PCs in Windows 10 News to solve the problem; A vulnerability in Intel chips that went undiscovered for almost a decade allows hackers to remotely gain full control over affected Windows PCs... Discussion in 'Windows 10 News' started by Borg 386, May 7, 2017.

  1. Borg 386 Win User

    Intel chip vulnerability lets hackers easily hijack fleets of PCs


    Intel chip vulnerability lets hackers easily hijack fleets of PCs | ZDNet
     
    Borg 386, May 7, 2017
    #1
  2. Geneo Win User

    Uh, their tools says based on the version of IME, my PC is not at risk. It also says the version of IME on my computer is "unknown". *Rolleyes Apparently Intel says consumer PC aren't vulnerable (ME vs. AMT I reckon).

    *** ME Information ***
    Version: Unknown
    SKU: Consumer
    State: None Detected
    Driver installed: False
    EHBCP Enabled: False
    LMS state: NotPresent
    MicroLMS state: NotPresent

    *** Risk Assessment ***
    Based on the version of the ME, the System is Not Vulnerable.

    :)
     
    Geneo, May 8, 2017
    #2
  3. how to I delete the update file for 2018-01 (KB4056892).

    Hello Greg,

    We’re aware of this industry-wide issue and have been working closely with chip manufacturers to develop and test mitigations to protect our customers. We are in the process of deploying mitigations to cloud services and are releasing security updates
    today to protect Windows customers against vulnerabilities affecting supported hardware chips from Intel, ARM, and AMD. We have not received any information to indicate that these vulnerabilities had been used to attack our customers.

    Kindly perform these quick steps to protect your PC against this security vulnerability, you may follow the steps provided in the article below.

    Protect your device against chip-related security flaws

    Regards.
     
    Vanessa Oca, May 8, 2017
    #3
  4. EDNCT Win User

    Intel chip vulnerability lets hackers easily hijack fleets of PCs

    Recent Windows Upgrade Fails

    The latest upgrade to Windows 10 has tried twice and failed BOTH times... Whenever I turn on or reboot my PC windows update hijacks my machine and fails to upgrade after an hour. (first time I let it go overnight) How do I get it to STOP!

    Further, once the old OS is recovered after rebooting twice Windows hijacks my internet connection to download it yet again.

    This update acts like a hijack virus... ransom ware. I need to use my PC and do not have time for this hacker garbage.
     
    EDNCT, May 8, 2017
    #4
  5. VBJP Win User
    Yes most consumer PCs should not be vulnerable. Only desktop boards with Q chip set (for example: Q77, Q87, Q170 etc.) paired with certain i5 or i7 CPUs that support vPro, and some business grade laptops like thinkpads etc. (usually have vpro sticker) are vulnerable.
    I have business grade ThinkPad that supports Intel AMT and is vulnerable also desktop with Q87 for now disabled AMT waiting for patches.

    Lenovo released statement with update schedule
    Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Remote Privilege Escalation

    For my Q87 board no news from Asus.
     
    VBJP, May 8, 2017
    #5
  6. qizz Win User
    It absolutely affects end users. The scope is unknown.

    Unfortunately, Intel's statement that 'Our Consumer Products Are Not Affected' has given a lot of people false confidence.

    My system (b85 4790k) returns 'vulnerable'.

    I know of at least two H87 owners getting the same results. H170 seems to have the same features.

    Hilariously, there isn't a BIOS setting to disable it on my system. No update/patch from Gigabyte either.

    What's worse, many people with problems around the launch of AU were told to install the Intel suite.

    Shutting the port should be enough. Should be. But the story has already grown in disastrousness a couple of times! I worry that we'll see trojans emerge that open the port as a possible attack vector.

    If you return positive, and are paranoid, the best technical advice I have heard is to not use the onboard LAN. The ME interface uses a layer 1-2 protocol to 'listen in' to traffic. It follows that it cannot listen in to another device (with a different MAC).
     
    qizz, May 8, 2017
    #6
  7. VBJP Win User
    There must be something wrong with that tool because neither B85 nor H170 or H87 support iAMT (also even with supported chipset for example Q87 that particular cpu 4790k will not work - no support for vPro), they just don't have network KVM or other services (can you open webpage with pc stats when you type that pcs ip from network?) maybe there is some local exploit for some intel ME functionality but don't think there is any remote/network exploits.
     
    VBJP, May 8, 2017
    #7
  8. Mystere Win User

    Intel chip vulnerability lets hackers easily hijack fleets of PCs

    It should be noted that if you are using any kind of physical firewall (Wireless router, cable modem with firewall, etc..) you won't be vulnerable. The machine has to be directly connected to the internet without a physical firewall (Software firwall probably won't work because the hardware itself is exposing the ports, before the OS is even running).
     
    Mystere, May 9, 2017
    #8
  9. VBJP Win User
    Most consumer routers even cheap ISP provided routers usually have some sort of firewall. That's why this vulnerability isn't that scary for most consumers. Except if someone gains access to local network or even that pc then it may do some damage. But some business/pro users that use intel AMT for controlling remote server/PC/etc. via internet (if you have remote server or pc to administer and need to have low level remote access, because RDP will not work for accessing BIOS or if windows crashed) may have opened that network interface to internet, then it's bad.
     
    VBJP, May 9, 2017
    #9
  10. eLPuSHeR Win User
    I ran the tool on my Haswell-E PC and it said I wasn't affected.
     
    eLPuSHeR, Apr 4, 2018
    #10
Thema:

Intel chip vulnerability lets hackers easily hijack fleets of PCs

Loading...
  1. Intel chip vulnerability lets hackers easily hijack fleets of PCs - Similar Threads - Intel chip vulnerability

  2. New vulnerability lets attackers sniff or hijack VPN connections

    in Windows 10 News
    New vulnerability lets attackers sniff or hijack VPN connections: Academics have disclosed this week a security flaw impacting Linux, Android, macOS, and other Unix-based operating systems that allows an attacker to sniff, hijack, and tamper with VPN-tunneled connections. The vulnerability -- tracked as CVE-2019-14899 -- resides in the...
  3. Intel Vulnerability Updates

    in Windows 10 Installation and Upgrade
    Intel Vulnerability Updates: I have several computers (both Win 7 & Win 10 Pro 64-bit) that require the updates for the Intel vulnerability problem that was released May 14. What I'm trying to figure out is how to download and install the microcode updates. Is it part of Windows update or something...
  4. Intel Bluetooth pairing vulnerability

    in Windows 10 News
    Intel Bluetooth pairing vulnerability: Intel ID: INTEL-SA-00128 Product family: Intel® Dual Band Wireless-AC, Intel® Tri-Band Wireless-AC and Intel® Wireless-AC family of products Impact of vulnerability: Escalation of Privilege, Denial of Service, Information Disclosure Severity rating: High Original release:...
  5. Hackers are exploiting an unpatched Flash Player vulnerability

    in AntiVirus, Firewalls and System Security
    Hackers are exploiting an unpatched Flash Player vulnerability: A update for flash player was released today (5/12/16) Adobe Systems is working on a patch for a critical vulnerability in Flash Player that hackers are already exploiting in attacks. The Flash Player vulnerability is being tracked as CVE-2016-4117 and affects Flash...
  6. Is Edge Easily Hijacked by Malicious Sites?

    in Browsers and Email
    Is Edge Easily Hijacked by Malicious Sites?: My impression of Edge is that it is easily hijacked by malicious sites. You know what I am talking about: it's the sites that say your computer is infected and you need to call some number, and Edge never lets you stop the popups to get out of the site (despite the Block...
  7. New Intel chip function ..?

    in Windows 10 Software and Apps
    New Intel chip function ..?: Hi All . I just notice there is an app/or Intel drive call Wake-On-Voice in my laptop , But my Processor is Intel Broadwell core i5-5200u , not Skylake .. ?? I don't know how to set it up either . Any idea ..? Thanks . 51044
  8. Intel Chip Set & Intel Management Engine Help

    in Windows 10 Drivers and Hardware
    Intel Chip Set & Intel Management Engine Help: Hello as Question title says. I'm having difficulty finding the drivers on the Intel website Support and Drivers menu. Drivers needed: Intel Chipset & Intel Management Engine Im using a Z170 motherboard with an I7 6700K. OS Windows 10 64Bit home edition. Any help...
  9. AMD on chip vulnerabilities reported by CTS Labs

    in Windows 10 News
    AMD on chip vulnerabilities reported by CTS Labs: On March 12, 2018, AMD received a communication from CTS Labs regarding research into security vulnerabilities involving some AMD products. Less than 24 hours later, the research firm went public with its findings. Security and protecting users’ data is of the utmost...
  10. Surface updates for recent chip-related security vulnerability

    in Windows 10 News
    Surface updates for recent chip-related security vulnerability: Introduction This article discusses the impact of the following security issue on Surface Devices: https://portal.msrc.microsoft.com/en...sory/ADV180002 Summary Microsoft is aware of a new publicly disclosed class of vulnerabilities referred to as “speculative...