News: 1637051344

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Intel's recent Atom, Celeron, Pentium chips can be lulled into a debug mode, potentially revealing system secrets

(2021/11/16)


Certain Intel processors can be slipped into a test mode, granting access to low-level keys that can be used to, say, unlock encrypted data stored in a stolen laptop or some other device.

This vulnerability ( [1]CVE-2021-0146 ), identified by Positive Technologies, a security firm [2]just sanctioned by the US, affects various Intel Atom, Celeron, and Pentium chips that were made in the past few years. It's [3]one of 25 security holes Intel revealed last week.

The insecure chip hardware permits the "activation of test or debug logic at runtime for some Intel processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access," Intel explained in an [4]advisory , which rates the bug with a CVSS score of 7.1. Exploitation of the hole does require physical access to the chips, an important caveat to note.

[5]

The vulnerable Atom, Celeron, and Pentium chips come from Intel's Apollo Lake, Gemini Lake, and Gemini Lake Refresh platforms, which serve as the brains in various desktop, mobile, and embedded systems.

[6]

[7]

One example cited is the Atom E3900 embedded processors that are found in more than 30 car models, according to Intel, and, [8]it's claimed , in Tesla's Model 3. These chips also drive assorted [9]network appliances and IoT devices.

The bug was identified by Mark Ermolov and Dmitry Sklyarov from Positive Technologies, and independent researcher, Maxim Goryachy, and was responsibly disclosed to Intel.

[10]AMD reveals an Epyc 50 flaws – 23 of them rated high severity. Intel has 25 bugs, too

[11]Do you want speed or security as expected? Spectre CPU defenses can cripple performance on Linux in tests

[12]Boffins find if you torture AMD Zen+, Zen 2 CPUs enough, they are vulnerable to Meltdown-like attack

[13]Re-volting: AMD Secure Encrypted Virtualization undone by electrical attack

Ermolov in [14]a statement warned that one way this bug might be abused would be if a miscreant obtained a stolen laptop or notebook computer with vulnerable hardware.

“Using this vulnerability, an attacker can extract the encryption key and gain access to information within the laptop," he explained.

[15]

"The bug can also be exploited in targeted attacks across the supply chain. For example, an employee of an Intel processor-based device supplier could, in theory, extract the Intel CSME firmware key and deploy spyware that security software would not detect."

An attacker can extract the encryption key and gain access to information within the laptop

Ermolov also said the bug can be abused to fetch the root encryption key that secures Intel Platform Trust Technology and Enhanced Privacy ID technologies. These are used, for example, to secure ebook content and prevent the unauthorized copying of protected content.

The bug arises from an insufficiently protected, overprivileged debugging system and the fix comes in the form of UEFI BIOS updates for affected devices.

Patches have already been issued by [16]Dell , [17]HP , [18]Lenovo , and [19]Supermicro , among others. ®

Get our [20]Tech Resources



[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0146

[2] https://www.theregister.com/2021/11/03/us_sanctions_spyware/

[3] https://www.theregister.com/2021/11/12/amd_and_intel_flaws/

[4] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZOPY8TBJoNh9jdeBM1jVwAAAQ4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZOPY8TBJoNh9jdeBM1jVwAAAQ4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZOPY8TBJoNh9jdeBM1jVwAAAQ4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://twitter.com/bozitatarevic/status/1068488652433616896

[9] https://www.axiomtek.com/Default.aspx?MenuId=Products&FunctionId=ProductView&ItemId=24444&C=NA345E&upcat=232

[10] https://www.theregister.com/2021/11/12/amd_and_intel_flaws/

[11] https://www.theregister.com/2021/06/22/spectre_linux_performance_test_analysis/

[12] https://www.theregister.com/2021/08/30/amd_meltdown_zen/

[13] https://www.theregister.com/2021/08/13/amd_secure_encrypted_virtualization/

[14] https://www.ptsecurity.com/ww-en/about/news/positive-technologies-discovers-vulnerability-in-intel-processors-used-in-laptops-cars-and-other-devices/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZOPY8TBJoNh9jdeBM1jVwAAAQ4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://www.dell.com/support/kbdoc/en-in/000193310/dsa-2021-235

[17] https://support.hp.com/us-en/document/ish_5031100-5031212-16/hpsbhf03756

[18] https://support.lenovo.com/us/en/product_security/LEN-75180

[19] https://www.supermicro.com/en/support/security_center

[20] https://whitepapers.theregister.com/



Bug my arse

Anonymous Coward

Another example of standard backdoors built-in to equipment manufactured by large American companies.

Doctor Syntax

Yet again I have to wonder about this trusted platform stuff. Just who is it who's supposed to trust it? Or is it a case of getting rid of the difficult bit in the title?

Oh please

Pascal Monett

" one way this bug might be abused would be if a miscreant obtained a stolen laptop or notebook computer with vulnerable hardware "

If he's got the laptop it's game over, no need to fiddle with the CPU.

He can just take the disk out, slap it into a USB receptacle and read anything he wants. If it's not encrypted, it's his to read.

How is this supposed to be a vulnerability ?

Re: Oh please

Duncan Macdonald

With this exploit, it would be possible to extract the encryption key and read the disk even if it was encrypted. (For full disk encryption to work on the OS disk, the encryption key must be stored somewhere on the motherboard or the OS would not be able to boot.)

Re: Oh please

Rabbit80

Since the chips affected are commonly found in embedded systems, cars etc then potentially an attacker could get baked in encryption keys that could for example allow them to push hacked software or firmware updates out to many devices - creating a much bigger security issue. They could also decrypt the encrypted file systems on such devices enabling them to find other security weaknesses.

Re Dark Clouds and Silver Linings .......Delivering Consequences to be Dealt with ASAP PDQ

amanfromMars 1

What do you think happens if the bug is not quashed nor quenched. Resist defence and what is there to attack and destroy/command and control?

Intel Processors would then become a vital cog in all future remote operations accessed for instruction and direction from computers.

Do humans realise that in the spaces and places that you visit and frequent? Do they never ask where their leaders orders come from.

The simple questions to ask are ... Are they entirely of their own making or are they from a Foreign Lead or an Alien Read from a Computer Feed ..... with that surely a Harvest to Exploit in Full Service of Outstanding Upstanding Enjoyment?

Quantum Communication Made Simple. Not for Dummies.

When a Bug is not a Bug is IT an Almighty Trojan ‽

amanfromMars 1

Exploitation of the hole does require physical access to the chips, an important caveat to note.

Exploitation is surely at ITs Best, a Virtual Application with ESPecial Permissions Granted for Future Trial Testing in Current Running Systems?

That's not a Bug, it's a Novel ACTivating Feature for Future Programs Deploying Applications Delivering Promises via Virtual Reality Promotions .....with Advanced IntelAIgent Intentions the Start and End of Every Worthy Powerful Goal to Improve and Try to Better and Mentor and Monitor.

Quite a lot alike a SMARTR Bigger Brother would Muster for Highland Gatherings. For Lairdly Views on Future Highland Clan Type Applications ...... for Above Top Secret IntelAIgent Service Operations.

Certain Intel processors have every right to be concerned if the above use of Intel platforms is to be of any negative concern rather than worthy of virtual encouragement for positive support to future chip designers doing the fabrication foundry thing. That's one very popular option favoured by a decidedly fanatical base exploring the desserts afforded to reinforce and assist unprecedented success in the myriad fields of true and/or original endeavours.

He's been like a father to me,
He's the only DJ you can get after three,
I'm an all-night musician in a rock and roll band,
And why he don't like me I don't understand.
-- The Byrds