U.S. Government Warns Businesses About Cyber Bug in Intel Chips
The Department of Homeland Security gave the guidance a day after Intel said it had identified security vulnerabilities in remote-management software known as "Management Engine".
The U.S. government on Tuesday urged businesses to act on an Intel Corp alert about security flaws in widely used computer chips as industry researchers scrambled to understand the impact of the newly disclosed vulnerability. The Department of Homeland Security gave the guidance a day after Intel said it had identified security vulnerabilities in remote-management software known as "Management Engine" that shipped with eight types of processors used in business computers sold by Dell Technologies, Lenovo Group Ltd, HP, Hewlett Packard Enterprise Co and other manufacturers.
Security experts said that it was not clear how difficult it would be to exploit the vulnerabilities to launch attacks, though they found the disclosure troubling because the affected chips were widely used. "These vulnerabilities affect essentially every business computer and server with an Intel processor released in the last two years," said Jay Little, a security engineer with cyber consulting firm Trail of Bits. For a remote attack to succeed, a vulnerable machine would need to be configured to allow remote access, and a hacker would need to know the administrator's username and password, Little said. Attackers could break in without those credentials if they have physical access to the computer, he said.
India's 1st Tech And Auto Show Awards 2017 | Vote And Win a Smartphone
Intel said that it knew of no cases where hackers had exploited the vulnerability in a cyber attack. The Department of Homeland Security advised computer users to review the warning from Intel, which includes a software tool that checks whether a computer has a vulnerable chip. It also urged them to contact computer makers to obtain software updates and advice on strategies for mitigating the threat.
Intel spokeswoman Agnes Kwan said the company had provided software patches to fix the issue to all major computer manufacturers, though it was up to them to distribute patches to computers users. Dell's support website offered patches for servers, but not a laptop or desktop computers, as of midday Tuesday. Lenovo offered fixes for some servers, laptops and tablets and said more updates would be available Friday. HP posted patches to its website on Tuesday evening.
Security experts noted that it could take time to fix vulnerable systems because installing patches on computer chips is a difficult process. "Patching software is hard. Patching hardware is even harder," said Ben Johnson, co-founder of cyber startup Obsidian Security.
Tech And Auto Show | EP21 | Apple iPhone X, Suzuki Intruder 150 & More
Get the best of News18 delivered to your inbox - subscribe to News18 Daybreak. Follow News18.com on Twitter, Instagram, Facebook, TikTok and on YouTube, and stay in the know with what's happening in the world around you – in real time.
Recommended For You
- OnePlus 7T, OnePlus 7T Pro Specifications Leak Claims to Reveal All New Features
- Sara Ali Khan Gets Papped Outside Rumoured Boyfriend Kartik Aaryan's House
- Is Facebook Ready For TV Battles With Netflix, Apple TV+ and Amazon Video?
- 5-Years-Old Recreates 'Up' Moment With Great Grandparents for Birthday Photoshoot
- A Pakistani Pop-Singer is Facing Legal Action for Threatening PM Modi with Snakes