logo
Positive Technologies researcher discovers a new exploitation vector for previously known vulnerabilities in Intel processors

Positive Technologies researcher discovers a new exploitation vector for previously known vulnerabilities in Intel processors

Zawya03-04-2025

Dubai, UAE: PT SWARM expert Mark Ermolov discovered a new exploitation vector for the vulnerabilities CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2019-0090, and CVE-2021-0146, which Intel has already fixed. Previously, these issues only enabled partial compromise, but this new method can lead to a complete security breach of affected platforms.
The newly discovered approach to exploitation can be applied to attacks on devices equipped with Intel Pentium, Celeron, and Atom processors from the Denverton, Apollo Lake, Gemini Lake, and Gemini Lake Refresh series. Production of these chips has ended, yet they remain in embedded systems, such as automotive electronics, and in ultra-mobile devices, including e-readers and mini-PCs. Intel was notified in accordance with the responsible disclosure policy but rejected the described problem and refused to take measures to eliminate or reduce the threat level.
The main exploitation vector involves supply chain attacks [1]. Attackers can embed spyware at the assembly or repair stage without altering the hardware.
"This approach requires no soldering or any other physical modification," said Ermolov. "Local access is enough to retrieve the encryption key and inject malicious code into Intel CSME firmware. These implants often slip under the radar of Intel Boot Guard, virtualization-based security (VBS), and antivirus solutions. They can operate unnoticed, capture user data, lock devices, erase or encrypt files, and carry out other destructive actions."
A secondary risk involves exploiting these formerly patched flaws to bypass DRM [2] safeguards, which can grant unauthorized access to content from various streaming services. The newly identified method also circumvents some Amazon e-reader protections, allowing threat actors to copy data on devices powered by vulnerable Intel Atom processors.
Attackers can also use these tactics to access data on encrypted storage devices like hard drives or SSDs. This approach can target laptops or tablets built on the at-risk processors.
In 2021, Positive Technologies worked with Intel to reduce the danger posed by CVE-2021-0146, which allowed extraction of the platform chipset key. That key is one of the Intel CSME subsystem's most closely guarded secrets because it underpins the root of trust and generates every working key for data encryption and code integrity. The new exploitation method decrypts the chipset key by bypassing its fuse encryption layer, opening the door to malicious uses.Mordor Intelligence ranks Intel as a leading chip supplier for IoT solutions. Its Atom E3900 processors, which are affected by the vulnerabilities, appear in devices used by dozens of automotive manufacturers. Organizations looking to maintain ongoing oversight of vulnerabilities can rely on MaxPatrol VM for continuous management. Should a breach occur, platforms like MaxPatrol SIEM can assist in spotting post-exploitation indicators and tracking further actions by attackers.
About Positive Technologies
Positive Technologies is an industry leader in results-oriented cybersecurity and a major global provider of information security solutions. Our mission is to safeguard businesses and entire industries against cyberattacks and non-tolerable damage. Over 4,000 organizations worldwide use technologies and services developed by our company. Positive Technologies is the first and only cybersecurity company in Russia to have gone public on the Moscow Exchange (MOEX: POSI), with 205,000 shareholders and counting. Follow us in the News section at ptsecurity.com.
[1] Attacks on service providers, through third-party companies.
[2] Digital rights management — technical means of copyright protection.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Intel makes new appointments in bid to be more engineering-focused
Intel makes new appointments in bid to be more engineering-focused

Tahawul Tech

timea day ago

  • Tahawul Tech

Intel makes new appointments in bid to be more engineering-focused

Intel recently hired three chip industry executives for roles in engineering and networking in an effort to overhaul top management. These comprise a part of CEO Lip-Bu Tan's plans turn around the embattled chipmaker by trimming the company's large workforce, hiring new leadership, focusing on customer satisfaction and ensuring the foundry business succeeds. Tan started to flatten Intel's leadership team since taking over as top boss in March with many important chip groups reporting directly into him, including sales veteran Greg Ernst, who was appointed chief revenue officer. Ernst previously served as Intel's head of U.S. sales and marketing operations. In keeping with its plans to become more engineering-focused, the company also tapped Srinivasan Iyengar, Jean-Didier Allegrucci and Shailendra Desai to lead engineering roles. 'Greg, Srini, J-D and Shailendra are highly accomplished leaders with strong reputations across our ecosystem and they will each play important roles as we position our business for the future,' Tan said. Iyengar joined Intel from Cadence Design Systems and will lead a new customer engineering centre, while Allegrucci, a former Rain AI executive, will manage the development of the AI System on Chip engineering. Desai, who joined Intel from Google, will head the development of new AI chip architectures. Iyengar will report into Tan, while Allegrucci and Desai will report into Sachin Katti, Intel's chief technology and AI officer. Source: Reuters Image Credit: Stock Image/Intel

Omnix International Launches Groundbreaking Ultra-High Performance HOT Systems Laptops for Demanding Power Users
Omnix International Launches Groundbreaking Ultra-High Performance HOT Systems Laptops for Demanding Power Users

Web Release

time2 days ago

  • Web Release

Omnix International Launches Groundbreaking Ultra-High Performance HOT Systems Laptops for Demanding Power Users

Omnix International, a regional leader in digital transformation and advanced technology solutions, today announced the official launch of its revolutionary HOT Systems professional laptops — the first 18 x 16-inch ultra-high performance models purpose-built for creative and technical professionals in the Middle East. Engineered for power, precision, and performance, the new HOT Systems laptops are equipped with cutting-edge Intel® Core™ Ultra 9 200HX and AMD Ryzen™ 9000 HX processors, and feature NVIDIA RTX™ 5080 and 5090 GPUs powered by Blackwell architecture. To ensure optimal thermal management under heavy workloads, the laptops incorporate advanced cooling innovations, including heat-pipe systems, redesigned high-efficiency fans, and optional liquid cooling technology — enabling users to push the boundaries of performance without compromise. Designed to meet the rigorous demands of AEC professionals, digital content creators, data scientists, and other high-performance users, the laptops deliver exceptional speed, multithreaded processing power, and unparalleled graphics capabilities. 'With the continued rise of digital transformation and the demand for mobile yet powerful computing, HOT Systems represents a new class of professional workstations,' said Walid Gomaa, CEO of Omnix. 'These laptops are not only precision-engineered for desktop-level performance on the go but also reflect our commitment to enabling professionals to achieve more, faster, and smarter.' Key Features Include: – Up to 128GB DDR5 6400 MHz RAM and PCIe Gen 5 SSDs for lightning-fast data processing – Wi-Fi 7, Thunderbolt™ 5, and Killer™ LAN for ultra-fast connectivity – Native support for 6K resolution displays, ideal for high-end visualization – NVIDIA GPUs optimized for AI, AR/VR, complex computations, and intensive AEC workflows – High refresh rates, visual fidelity designed, and true-to-life color accuracy At the heart of the platform lies Omnix intellectual property Hardware Optimization Technology (HOT), ensuring tight hardware-software integration and enhnaced stability for industry-standard applications such as Autodesk, Adobe, Rhino, Lumion, Unity3D, Enscape, Dassault Systèmes, ArcGIS, Ansys, and more. Joseph John, Regional Sales Manager for HOT Systems at Omnix, added: 'With a keen focus on our customers' evolving demands and our commitment to staying ahead of the curve, we've engineered these laptops to address the evolving needs of professionals in the region. By prioritizing compatibility, high performance, and reliability, we empower users to stay productive and innovation-driven—without being constrained by technical limitations.' Each HOT Systems laptop is backed by Omnix's renowned technical support team and includes a comprehensive 3-year warranty, reflecting the company's continued dedication to service excellence and customer satisfaction.

Omnix International Unveils HOT Systems Laptops for Professionals
Omnix International Unveils HOT Systems Laptops for Professionals

TECHx

time3 days ago

  • TECHx

Omnix International Unveils HOT Systems Laptops for Professionals

Home » Product Watch » Omnix International Unveils HOT Systems Laptops for Professionals Omnix International announces the launch of its HOT Systems professional laptops, the first 18 x 16-inch ultra-high-performance models designed for creative and technical professionals in the Middle East. Engineered for power, precision, and performance, the new HOT Systems are equipped with cutting-edge Intel® Core™ Ultra 9 200HX and AMD Ryzen™ 9000 HX processors, alongside NVIDIA RTX™ 5080 and 5090 GPUs powered by Blackwell architecture. To keep performance strong under heavy workloads, the laptops incorporate advanced cooling innovations, including heat-pipe systems, redesigned high-efficiency fans, and optional liquid-cooling technology, enabling users to push the boundaries without compromise. Designed to meet the rigorous demands of AEC professionals, digital content creators, data scientists, and other high-performance users, the HOT Systems deliver exceptional speed, multithreaded processing power, and unparalleled graphics capabilities. 'With the continued rise of digital transformation and the demand for mobile yet powerful computing, HOT Systems represent a new class of professional workstations,' said Walid Gomaa, CEO of Omnix. 'These laptops are not only precision-engineered for desktop-level performance on the go but also reflect our commitment to enabling professionals to achieve more, faster, and smarter.' Key Features Include: Up to 128GB DDR5 6400MHz RAM and PCIe Gen 5 SSDs for lightning-fast data processing Wi‑Fi 7, Thunderbolt 5, and Killer LAN for ultra-fast connectivity Native support for 6K resolution displays, ideal for high-end visualization NVIDIA GPUs optimized for AI, AR/VR, complex computations, and intensive AEC workflows High refresh rates, color fidelity, and true-to-life color accuracy At the heart of the platform lies Omnix's intellectual property, Hardware Optimization Technology (HOT), ensuring tight hardware-software integration and enhanced stability for industry-standard applications, including Autodesk, Adobe, Rhino, Lumion, Unity3D, Enscape, Dassault Systèmes, ArcGIS, Ansys, and more. Joseph John, Regional Sales Manager for HOT Systems at Omnix, added: 'With a keen focus on our customers' evolving demands, we've engineered these laptops to address their growing needs. We're empowering users to stay productive and innovation-driven, without being constrained by technical limitations.' Each HOT Systems laptop comes backed by Omnix's renowned technical support team and a comprehensive 3-year warranty, reflecting its continued dedication to service excellence and customer satisfaction.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store