Skip to main content

Intel Critical Privilege Escalation Vulnerability

A newly patched flaw found in a number of Intel's remote management technologies have been found to have held a highly critical privilege escalation vulnerability, leaving seven years' worth of chipsets vulnerable to attack.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A newly patched flaw found in a number of Intel's remote management technologies have been found to have held a highly critical privilege escalation vulnerability, leaving seven years' worth of chipsets vulnerable to attack.

Threat details

Successful exploitation can result in an attacker gaining complete control of a vulnerable system. The vulnerability can be exploited remotely, however the limiting factor of access to the required ports (TCP 16992 and 16993) restricts the likelihood of a remote attack and is more likely to be in used as an aid for lateral movement in a compromised network.

With access to a vulnerable system, an attacker is able to access an array of functionality including the KVM function that gives a user hardware level control over the keyboard and mouse. Code can be loaded remotely, files can be read and written to, boot priority can be modified to launch malicious boot images and more. Due to the intended purpose of the functionality, an attacker gains full control of all system administrator functionality on the target system.

For further information:


Remediation steps

Type Step
  • Ensure available patches are applied at the earliest opportunity
  • Ensure any devices with Intel remote administrative capabilities are securely firewalled off from untrusted networks.


CVE Vulnerabilities

Last edited: 17 February 2020 11:32 am