An unfixable flaw in nearly all Intel chips released in last five years allows sophisticated attackers access to mask ROM of its chipsets and microprocessors
This is the latest entry in a decade-long pattern around Intel's embedded management silicon. In 2017 the company patched a remote exploit affecting chips back to 2008 with Active Management Technology enabled (chips from 2008–2017), after advisories from HP and Lenovo; in 2018 it fixed longstanding Management Engine flaws but left the first three Core generations unpatched (first three Core generations).
What makes the CSME disclosure different is scope and permanence: earlier flaws lived in patchable firmware, while this one sits in mask ROM burned into the chip, targeting the very root of trust those earlier patches relied on. It converts Intel's security architecture from a fixable layer into an inherited liability across five years of shipping silicon.
First-order effects
Enterprises running recent Intel fleets cannot patch their way out — mitigations can only reduce exposure, so every machine with an affected CSME carries the risk for its full service life.
Second-order effects
Security teams lose the assumption that Intel's on-die root of trust is trustworthy, strengthening procurement cases for AMD and ARM-based platforms and pushing buyers toward external attestation and hardware security modules.
Third-order effects
If mask ROM roots of trust are structurally unfixable, industry trust migrates toward verifiable, externally auditable attestation rather than vendor-burned secrets — and later disclosures like the 2020 secure-enclave leak suggest the management-engine attack surface keeps yielding findings.
The trend: Intel's embedded management engines have become a recurring, hard-to-patch attack surface, steadily eroding confidence in vendor-controlled roots of trust and pushing enterprise security toward external attestation.
“Intel CSME bug is worse than previously thought. Researchers say a full patch requires replacing hardware. Only the latest Intel 10th generation CPUs are not affected.” https://www.zdnet.com/...
This is what we've been predicting for years. “A single key is used for an entire generation of Intel chipsets.” “... extracting this key is only a matter of time.” AMD mandates similar PSP in all CPUs inc. Epyc / Ryzen. Switch to #OpenPOWER today! https://www.theregister.co.uk/ …
Cast your minds back to when this bug was apparently fixed in Intel's firmware. Turns out it's not actually fixable. You need physical access to exploit but even so unless you've got 10th generation Intel chip it will persist https://www.ptsecurity.com/...
ICYMI: Pretty fun find in the lowest levels of Intel's chipset security. There's a small window of opportunity to hijack the Management Engine, when a computer turns on, for instance, and potentially acquire crucial crypto-keys from the hardware https://www.theregister.co.uk/ ...
Unfixable vulnerability found on Intel chips. The ROM of CSME is vulnerable which breaks the root of Trust. “The vulnerability allows extracting the Chipset Key and manipulating part of the hardware key and the process of its generation.” http://blog.ptsecurity.com/... https://tw…
Positive Technologies continue to point out problems with Intel's Management Engine. This one is interesting, it's a boot race condition that can be used to hijack it via DMA. https://www.theregister.co.uk/ ...
Color me surprised. Intel CPUs and chipsets have a concerning flaw that's unfixable. Intel x86 Root of Trust: loss of trust https://blog.ptsecurity.com/ ...
“[B]ecause this vulnerability allows a compromise at the hardware level, it destroys the chain of trust for the platform as a whole”. Great work by @_markel___ and team @ptsecurity_uk, and nice write-up by @dangoodin001. https://twitter.com/...
While attacks would be hard, the breadth of the impact would be huge. That means the flaw would likely be exploited only by nation states or other extremely advanced hackers. Other details here: https://arstechnica.com/... 6/x
This vulnerability resides in mask ROM that's used to boot the very 1st piece of firmware used by the Converged Security and Management, which implements the firmware-based Trusted Platform Module, authentication of UEFI BIOS & several other silicon-based security features. 1/x h…