Flaw in Intel chipsets' remote management allows hijacking using any authentication string; HP, Lenovo, others issue advisories; Intel expects patches this week
Patch for severe authentication bypass bug won't be available until next week. — A remote hijacking flaw that lurked …
Context & Ripple Effects
This is the second escalation in a week: Intel had just shipped a fix for a remote exploit hitting chips back to 2008 via Active Management Technology, only to concede the flaw is worse than first assessed — an authentication bypass that accepts any string. The difference matters because AMT's whole purpose is out-of-band access, so the bypass hands attackers the management plane itself.
The advisory wave from HP, Lenovo and other OEMs reflects how firmware bugs propagate: Intel writes the code, but PC makers own the update channel, and each must validate and repackage the fix for its own fleets before users see it.
First-order effects
- Enterprises with AMT-enabled machines are exposed to full remote hijacking until Intel's expected patch lands, with HP and Lenovo telling customers which of their systems are affected.
Second-order effects
- OEMs absorb the patching burden: every affected machine needs a vendor-validated firmware update pushed through IT management tools, straining enterprise patch cycles for a chip-level bug they did not write.
Third-order effects
- The pattern — repeated management-engine vulnerabilities culminating years later in flaws researchers deemed effectively unfixable at the silicon level — points toward durable skepticism about always-on out-of-band management co-processors in commodity PCs.
The trend: Intel's embedded out-of-band management silicon keeps resurfacing as an attack surface whose fixes flow slowly through OEM validation, making firmware patch latency the real security bottleneck.