3 ms·
A vulnerability has been found in the ROM of the Intel Converged Security and Management Engine (CSME). A reference to the specific vulnerability would be nice
by shiblukhan 7y ago
A vulnerability has been found in the ROM of the Intel Converged Security and Management Engine (CSME).
A reference to the specific vulnerability would be nice. CVE? Conference presentation? El Reg? Sketchy blogspam? Maybe I've been living under a rock, but it would still help the reader out.
- notpeter 7y agoThe article mentions CVE-2019-0090 and Intel acknowledges the author (Mark Ermolov of Positive Technologies) in their advisory. You haven't been living under a rock, this is a primary source and the first public suggestion of the grave severity of the vulnerability. "CVE-2019-0090 was initially found externally by an Intel partner and subsequently reported by Positive Technologies researchers. Intel would like to thank Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy from Positive Technologies for reporting this issue." https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0090 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0090 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html https://www.intel.com/content/www/us/en/security-center/advi...