One of the most important points for any company is having a solid management platform (whether remote or not). Intel offers that capability through Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability, and the news is that it just fixed a bug in multiple firmware versions tied to those technologies. The problem is that the vulnerability is seven years old, it is critical, and distributing the patch will require a titanic effort.
Almost a year ago we explored the Intel Management Engine, its potential as a backdoor, and the risks associated with an exploit. The idea that a processor and/or chipset has a very low-level remote management system is a bit uncomfortable, but the truth is that many companies depend on it. Well... guess what? Intel's management framework has been vulnerable for the last seven years, and perhaps a bit longer. Intel has already published the relevant patch for firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 of its Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability technologies. The classification says it all: privilege escalation. In theory, the bug does not reach general consumer PCs, but the list of affected systems published by Lenovo suggests otherwise.
The good news is that the affected functions come disabled by default in most cases, and many solutions meant for individual users do not even allow activation. The bad news is that with a little help from Shodan, experts have detected nearly 6,500 devices with the right conditions (say, AMT fully in use and ports 16992 and 16993 open) to suffer a remote attack. Of course, someone with physical access to a terminal could exploit the vulnerability, but that would be just an item on the list. In addition to the patch, Intel shared a series of recommendations for administrators, especially those working on Windows with "untrusted" users.
Basically, the number one suggestion is to verify that AMT is disabled. If that is not an option, the next step is to check for updates from the manufacturer (Intel published the patch for OEMs, not for end users). However, the number of systems out of warranty or with extended support already ended is enormous...
Source: Source:
Source: Source: