New Intel Vulnerability found, Converged Security and Management Engine exploitable

Published by

Click here to post a comment for New Intel Vulnerability found, Converged Security and Management Engine exploitable on our message forum
https://forums.guru3d.com/data/avatars/m/260/260828.jpg
Another month another vulnerability.
https://forums.guru3d.com/data/avatars/m/236/236670.jpg
Beware the stranger with the thumb drive at your computer! And don't take candy from strangers...
https://forums.guru3d.com/data/avatars/m/232/232130.jpg
airbud7:

Beware the stranger with the thumb drive at your computer! And don't take candy from strangers...
And hope it's not Intel in your pants.
https://forums.guru3d.com/data/avatars/m/122/122801.jpg
LOLZ^ And now back to your corona Fear mongering..........
https://forums.guru3d.com/data/avatars/m/236/236670.jpg
You park your car at work and start walking to your office building. You look down and see a shiny new 32GB thumb drive lying on the path. You think someone must have dropped it, so you pick it up, put it into your pocket, and go up to your office. Since you’re a good human being, you want to return it to whoever lost it, in case there are important work documents or someone’s novel-in-progress on there. So, you do what most people would do and plug it into your computer in the hopes of finding something on the drive that identifies the owner. This, my friend, is what’s known in the world of infosecurity as a ‘candy drop’ - an intentionally placed USB device dropped in plain sight, which tempts a target to pick it up and plug it in.
https://forums.guru3d.com/data/avatars/m/230/230258.jpg
airbud7:

You park your car at work and start walking to your office building. You look down and see a shiny new 32GB thumb drive lying on the path. You think someone must have dropped it, so you pick it up, put it into your pocket, and go up to your office. Since you’re a good human being, you want to return it to whoever lost it, in case there are important work documents or someone’s novel-in-progress on there. So, you do what most people would do and plug it into your computer in the hopes of finding something on the drive that identifies the owner. This, my friend, is what’s known in the world of infosecurity as a ‘candy drop’ - an intentionally placed USB device dropped in plain sight, which tempts a target to pick it up and plug it in.
Well, COVID-19 Fear ,my firend , will help that person to prevent himself from this kind of mishaps . How? Go figure:p
data/avatar/default/avatar04.webp
Having an Intel CPU is more dangerous than running naked through a vaporized COVID-19 cluod.
https://forums.guru3d.com/data/avatars/m/236/236670.jpg
mohiuddin:

Well, COVID-19 Fear ,my firend , will help that person to prevent himself from this kind of mishaps . How? Go figure:p
better have plastic gloves on before you pick up that infected thumb drive 😛
https://forums.guru3d.com/data/avatars/m/165/165018.jpg
airbud7:

Beware the stranger with the thumb drive at your computer! And don't take candy from strangers...
if a stranger with a thumb drive makes it to my computer all that the’ll have left is a thumb....
https://forums.guru3d.com/data/avatars/m/122/122801.jpg
Scratches head, huh? Me no likely! 😕
https://forums.guru3d.com/data/avatars/m/53/53598.jpg
Intel, the gift that keeps on giving.
https://forums.guru3d.com/data/avatars/m/246/246171.jpg
airbud7:

You park your car at work and start walking to your office building. You look down and see a shiny new 32GB thumb drive lying on the path. You think someone must have dropped it, so you pick it up, put it into your pocket, and go up to your office. Since you’re a good human being, you want to return it to whoever lost it, in case there are important work documents or someone’s novel-in-progress on there. So, you do what most people would do and plug it into your computer in the hopes of finding something on the drive that identifies the owner. This, my friend, is what’s known in the world of infosecurity as a ‘candy drop’ - an intentionally placed USB device dropped in plain sight, which tempts a target to pick it up and plug it in.
Run a Linux live CD/USB to open it up. Not only will it not run any automated binaries, but even if it does, you've basically got a sandbox OS running entirely in RAM for it to destroy instead of anything actually important. If you find it was honestly someone's missing drive, great - you get to return it. If you find it was a ploy to steal your information or ruin your day, great - just format the drive and now you've got a 32GB drive for free. Win-win.
data/avatar/default/avatar39.webp
Kool64:

if a stranger with a thumb drive makes it to my computer all that the’ll have left is a thumb....
Case with teeth? That sounds like guru3D case of the month material!
https://forums.guru3d.com/data/avatars/m/247/247876.jpg
Crazy Serb:

Case with teeth? That sounds like guru3D case of the month material!
Hey, do you know a guru CrazY_Milojko by chance? I miss him...
https://forums.guru3d.com/data/avatars/m/247/247876.jpg
schmidtbag:

Run a Linux live CD/USB to open it up. Not only will it not run any automated binaries, but even if it does, you've basically got a sandbox OS running entirely in RAM for it to destroy instead of anything actually important. If you find it was honestly someone's missing drive, great - you get to return it. If you find it was a ploy to steal your information or ruin your day, great - just format the drive and now you've got a 32GB drive for free. Win-win.
What about malware firmware? (Or even a spying SoC instead of plain USB electronics...) PS Nice name for a music band "Malware Firmware", eh?
https://forums.guru3d.com/data/avatars/m/191/191875.jpg
airbud7:

You park your car at work and start walking to your office building. You look down and see a shiny new 32GB thumb drive lying on the path. You think someone must have dropped it, so you pick it up, put it into your pocket, and go up to your office. Since you’re a good human being, you want to return it to whoever lost it, in case there are important work documents or someone’s novel-in-progress on there. So, you do what most people would do and plug it into your computer in the hopes of finding something on the drive that identifies the owner..
Look we know fine well the only reason anyone is checking out that drive is to see what kind of porn is on it. I would say something stupid like I am glad I went AMD this time round but given that most of these vulnerabilities require what amount to direct access to my computer to be of any reals threat I suspect that the model of CPU I am using would be the least of my concerns.
https://forums.guru3d.com/data/avatars/m/165/165018.jpg
Crazy Serb:

Case with teeth? That sounds like guru3D case of the month material!
More like an industrial grinder but yes.....
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
YAY wait BOOO Waits for held line " human" are flawed and are "security risk" head to nears human recycling plant for re purposing. Seriously thought this getting rather stupid they are just looking for flaws at this point and released it to public to cause things, Before the whole Meltdown/spectre thing there was very lil of this news now it like the in thing to do. AMD already had "new" architecture with ryzen, so they spare at lest till all these people that out Intel flaws turn the attention to AMD. Intel been using same architecture for better part of decade with the iX cores? Even if Intel were to announced new architecture ( from the ground up) it would be years before its ready, and even when it is they would just start picking that apart, cause the in thing to to look for flaws. There will always be flaws and security issue in all tech. there no need to purpose go out ones way to find them put all that info out in the public for all to know and make things worse. I get these thing should be fixed, but it shouldnt be outed to public so everyone knows include the shady people that would use those flaws, but didnt know about till it was outted publicly
https://forums.guru3d.com/data/avatars/m/246/246171.jpg
mbk1969:

What about malware firmware? (Or even a spying SoC instead of plain USB electronics...)
When it comes to firmware, I figure the worst-case scenario is it will either depend on software on the drive itself to do damage, or, it will just simply damage the files on the drive (better that than anywhere else). For example, there are those drives that lie about their capacities - that's basically malware firmware. As for a whole SoC, a live OS will still protect it from doing any real harm if the primary goal is to just see what's on the "drive". There's only so much those things can do.
https://forums.guru3d.com/data/avatars/m/247/247876.jpg
schmidtbag:

When it comes to firmware, I figure the worst-case scenario is it will either depend on software on the drive itself to do damage, or, it will just simply damage the files on the drive (better that than anywhere else). For example, there are those drives that lie about their capacities - that's basically malware firmware. As for a whole SoC, a live OS will still protect it from doing any real harm if the primary goal is to just see what's on the "drive". There's only so much those things can do.
What about user using the thumb on his main OS after he wiped the thumb (thinking he is safe)?