After Spectre & Meltdown, Intel Faces an Evil Maid Problem

  /     /     /  
Publicated : 22/11/2024   Category : security


After Spectre & Meltdown, Intel Faces an Evil Maid Problem


In a rough start to 2018, Intel is dealing with the Spectre and Meltdown vulnerabilities in its CPUs, and now the chip maker is confronting reports of a flaw that leaves chips open to an Evil Maid attack.



Its only a few weeks old, but 2018 has not been a good year for Intel.
Since the start of the year, most tech headlines have focused on the major problems and security flaws that have been found in Intels CPU designs -- now referred to as Spectre and Meltdown -- as well as reports of security holes in the Advanced Management Technology (AMT) program that runs the bits through the processors. (See
Security Warning: Intel Inside
.)
Now, add one more problem to the list.
Harry Sintonen, a senior researcher at F-Secure Corp. ,
announced last week
that he had found a way for someone who gains physical access for under 60 seconds to a computer that uses an Intel Corp. (Nasdaq: INTC) CPU to be able to poison it so that it could be hijacked remotely if the attacker is on the same network.
This kind of attack is called an
Evil Maid
-- a machine left open for a moment public space could be compromised by a threat actor. This type of attack takes its name from the scenario of an evil maid who carries out the attack on a computer that is left in a hotel room.
(Source:
StockSnap via Pixabay
)
The attack is simple and deadly.
Booting up the device and pressing CTRL-P during the process starts it. This causes the attacker to log in to the Intel Management Engine BIOS Extension (MEBx), which has credentials that are unrelated to any other system passwords, TPM pin or Bitlocker settings. The usual MEBx default password admin will gain access to the AMT on most machines.
The attacker could then reset the default password, enabling remote access and setting AMTs user opt-in to None.
Boom -- a compromised machine. All the other passwords and logins in effect can be bypassed remotely if the attacker is on the same network segment. If the attackers get AMT to log into their own server, they dont even have to be on the same network segment to control the machine.
So, what can you do about this? One answer is to just throw out AMT but an IT department may not be able to do this remotely.
F-Secure seems to understand that, and offers the following advice:

Our recommendation is to query the amount of affected assets remotely [to find the machines with a non-admin MEBx password], and try to narrow the list down to a more manageable number. Organizations with Microsoft environments and domain connected devices can also take advantage of the System Center Configuration Manager to provision AMT.

There is no CVE number for this problem, nor is there any announcement scheduled from Intel. Organizations are on their own, here.
While Intel has written guides to dealing with AMT, the company may not have considered how the real world or evil maids can affect security. Leaving a laptop unsecured in a public place is never a good idea, in any case.
Related posts:
Meltdown & Spectre News Gets Worse – & Better
New Intel Vulnerability Hits Almost Everyone
Intel Management Engine Has a Big Problem
— Larry Loeb has written for many of the last centurys major dead tree computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Last News

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
After Spectre & Meltdown, Intel Faces an Evil Maid Problem