Intel fixes longstanding Intel Management Engine flaws that let hackers on same subnet run arbitrary code; first 3 generations of Core chips won't get patches
Richard Chirgwin / The Register :
Context & Ripple Effects
This fix lands on top of a year of escalating Intel firmware disclosures: May's remote-management hijack that worked with any authentication string — first downplayed, then confirmed worse in Intel's own severity upgrade — followed by the patch for chips dating back to 2008 with Active Management Technology enabled. By November, PC vendors were scrambling to ship firmware updates across millions of devices.
The headline change here is who gets left behind: Intel is patching the same-subnet arbitrary-code holes in the Management Engine but drawing the support line at fourth-generation Core, stranding owners of the first three generations. Given that the Management Engine runs below the OS, no operating-system update can compensate — the only remediation for those machines is isolation or retirement.
First-order effects
- Enterprises still running 1st- through 3rd-gen Core machines inherit permanently vulnerable firmware: any attacker on the same subnet can run arbitrary code on those hosts, forcing security teams to segment or decommission fleets that are otherwise functional.
- Organizations on supported silicon face another firmware patch cycle across their estates, repeating the vendor-scramble dynamic from the November disclosures.
Second-order effects
- IT buyers start pricing end-of-firmware-support into hardware refresh decisions, accelerating replacement demand for pre-4th-gen fleets and pushing vendors to advertise longer firmware maintenance windows as a differentiator.
Third-order effects
- Embedded management silicon like the Management Engine hardens into a structural liability: because it sits beneath the OS and outlives software patching, it converts every disclosed flaw into a forced hardware-refresh event — a pattern the corpus extends with 2020's unfixable mask-ROM flaw and partially patched enclave-leak bugs in later Intel silicon.
The trend: Chip-level management firmware is becoming a permanent, OS-independent attack surface whose patch cutoffs effectively set enterprise hardware refresh cycles.