Intel patches a nine year old flaw in remote management firmware

Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Escalation of Privilege vulnerability is reported by Intel as NOT affecting any consumer products as of the latest update on their site. That being said I have seen a lot of home based computers utilizing V-Pro technology which is indeed affected by this vulnerability. Explaining things even further THIS is the very reason Microsoft created the disallowed list of CPU support when releasing Windows 10. Please pass along as appropriate and get the word out.

 

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr

Intel has released a downloadable discovery tool located at downloadcenter.intel.com, which will analyze your system for the vulnerability.

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr 


338 half.png

floplot:

Norton Security Premier received an update to v20170510.001 on Wed. night around 7:30 PM EDT.

Hi David Almada SD:

Further to floplot's comment, it looks like Norton products are now covered for Web Attack: Intel AMT Privilege Escalation CVE-2017-5689 as well.  See the link for Security Update 1811 at https://www.symantec.com/en/ca/security_response/securityupdates/list.jsp?fid=nis&pvid=nis.

Run a manual LiveUpdate and then check your Intrusion Prevention security history (Security | History | Show | Intrusion Prevention) to confirm you've received IPS definition set v20170510.001 or later.

------------
32-bit Vista Home Premium SP2 * Firefox ESR v52.1.1 * NS Premium v22.9.1.12 * MBAM Premium v2.2.1

Hello

Norton Security Premier received an update to v20170510.001 on Wed. night around 7:30 PM EDT.

Thanks.

lmacri:

You would have to Live Chat with Norton Customer Support at www.norton.com/chat to confirm but I don't believe that Norton currently protects you from this exploit...

 Hi David Almada SD:

Further to my previous post, the signature for Web Attack: Intel AMT Privilege Escalation CVE-2017-5689 is now appearing on Symantec's list of exploits monitored by Intrusion Prevention at https://www.symantec.com/security_response/attacksignatures/#W and Symantec Endpoint Protection (Symantec's product for small businesses) just received IPS definition update v20170510.011 that adds protection for this exploit - see https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=sep&pvid=sep1213&year=2017&suid=SEP_Jaguar-SU1526-20170510.011.

Norton home consumer products haven't received an IPS Definition update via LiveUpdate that includes coverage for CVE-2017-5689 - at least not yet.  According to the update history at https://www.symantec.com/en/ca/security_response/securityupdates/list.jsp?fid=nis&pvid=nis our latest available IPS definition update is currently v20170509.001.
------------
32-bit Vista Home Premium SP2 * Firefox ESR v52.1.1 * NS Premium v22.9.1.12 * MBAM Premium v2.2.1

David Almada SD:

Hi, what does this site contain?  Could you post the text?

Well, for example....from the information discussed on Wilders. 
I located my processor thru "You can check your CPUs for vPro etc at https://ark.intel.com/#@Processors" and read Intel® vPro™ Technology ‡ No <here>.

But, I also ran commands <here> just to see. 

David Almada SD:

..Thousands of devices could be vulnerable to an Intel security flaw that allows hackers to remotely hijack computers. The company said that systems — including desktops, laptops, and servers —dating back as early as 2010 are affected by the flaw. Patch won’t be available until next week.  DOES NORTON PROTECT MY INTEL LAPTOP?

Hi David Almada SD:

You would have to Live Chat with Norton Customer Support at www.norton.com/chat to confirm but I don't believe that Norton currently protects you from this exploit.

Symantec has posted a security advisory for this exploit (CVE-2017-5689) on their Security Response site at Web Attack: Intel AMT Privilege Escalation CVE-2017-5689, but this exploit isn't included in the full list of attack signatures at https://www.symantec.com/security_response/attacksignatures/#I that are currently detected by Norton's Intrusion Prevention System.  I couldn't find CVE-2017-5689 in the current list of Vulnerabilites (i.e., CVE numbers) that Symantec protects against at https://www.symantec.com/security_response/landing/vulnerabilities.jsp either.

If you're concerned that your computer is vulnerable, a good place to start is the Intel news release Important Security Information about Intel Manageability Firmware as well as the Intel security advisory INTEL-SA-00075 mentioned in SoulAsylum's original post. That security advisory notes that "This vulnerability does not exist on Intel-based consumer PCs with consumer firmware", and you would have to have a high-end Intel Core vPro processor that has Intel Active Management Technology (a remote management feature), Intel Small Business Technology, or Intel Standard Manageability support enabled to be affected.  That security advisory has a link to the  INTEL-SA-00075 Discovery Tool that can be run on Win 7 and Win 10 machines to see if they are vulnerable.

I've been following the AskWoody.com discussion at Critical Elevation of Privilege Vulnerability in Various INTEL Firmware and unless you use a business PC or workstation I don't think you need to be overly concerned about this exploit.
------------
32-bit Vista Home Premium SP2 * Firefox ESR v52.1.1 * NS Premium v22.9.1.12 * MBAM Premium v2.2.1

Hi, David. Click on bjm_'s link. It's secure.

Hi, what does this site contain?  Could you post the text?

https://www.wilderssecurity.com/threads/for-those-who-own-intel-cpu-and-value-privacy.393172/

Warning: Intel bug worse than feared
Updated 5/8/2017
Thousands of devices could be vulnerable to an Intel security flaw that allows hackers to remotely hijack computers. The company said that systems — including desktops, laptops, and servers —dating back as early as 2010 are affected by the flaw. Patch won’t be available until next week.  DOES NORTON PROTECT MY INTEL LAPTOP?