­
Intel patches 9 vulnerabilities in their management platform - All Articles - CISO Platform

8669834700?profile=original

Intel has released patches for several security vulnerabilities in their Active Management Technology (AMT) and Intel Standard Manageability (ISM) platforms.  One of them was a critical flaw in AMT that allowed remote privilege escalation  CVE-2020-8758

It is nice to see more Intel product vulnerabilities are being addressed, especially those that reside in embedded management functions for business class CPU products. 

Compromising the hardware and firmware represent a serious threat to computing that can undermine all other security and monitoring controls that run on the system. Given the range of version numbers, I would guess these vulnerabilities have existed for years.

Properly investing in product security and standing by those products is crucial for trust. 

Of note, those customers who have Intel systems with older versions of Intel AMT (3.x thru 10.x) are not supported by Intel any longer and weren’t assessed for these vulnerabilities. Intel’s product security website (https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00404.html) states they are not planning any patch release for those versions. Customers are on their own to address those potentially Critical level vulnerabilities.

Votes: 0
E-mail me when people leave their comments –

CISO and Cybersecurity Strategist

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

Fireside Chat With Dan Bowden (Global Business CISO, Marsh McLennan (Marsh, Guy Carpenter, Mercer, Oliver Wyman))

  • Description:

    We’re excited to bring you an insightful fireside chat on "Navigating the Cyber Insurance Landscape: Key Considerations for CISOs" with Dan Bowden (Global Business CISO, Marsh McLennan) and Erik Laird (Vice President - North America, FireCompass). In this fireside chat, we'll decode the complexities of cyber insurance from a CISO’s lens and uncover how to make smarter, security-aligned decisions when it comes to policy design, claims, and ROI.

    As cyberattacks grow in…

  • Created by: Biswajit Banerjee
  • Tags: ciso, cyber insurance, dan bowden

CISO Platform: CISO 100 Awards & Future CISO Awards @ Atlanta

  • Description:

    Nominate for the CISOPlatform CISO 100 Awards & Future CISO Awards - Recognizing Cybersecurity Leaders. Recommend someone you know deserving of this prestigious accolade....Nominate your colleague, mentor, someone you admire or yourself !

    CISO Platform is collaborating as a community partner with EC-Council’s Global CISO Forum, supporting initiatives such as the CISO Platform…

  • Created by: Biswajit Banerjee