Skip to main content

Three generations of Intel processors are vulnerable to management engine bug

Intel
Image used with permission by copyright holder
It’s rare that the kids, parents, and grandparents are affected by any one problem, but that’s exactly what’s happened with the case of the recently discovered Management Engine bug in Intel processors. The exploit, which makes it possible for the remote takeover of a system, affects not only the latest, eighth generation of Intel CPUs, but the seventh and sixth generations as well (even the best ones).

But this bug doesn’t stop there. On top of affecting almost all desktop and laptop systems sold with Intel hardware since 2015, Xeon processor lines like the E3-1200 v5 and V6 are affected too. As Ars Technica points out, this bug also hits the Atom range of C3000 processors, the E3900 series for Internet of Things devices, and the Apollo Lake Pentium and Celeron N and J series processors.

The problem in Intel’s Management Engine (ME) firmware actually enables four different potential exploits, with different versions of the ME affected by different ones. The most severe bug was discovered by researchers in the latest version of the firmware; it allows remote code execution, which potentially allows the takeover of an entire system without having access to the hardware.

Other, somewhat less serious exploits, make it possible to cause system crashes or instability, and to access privileged information about the system.

Despite the widespread nature of the bug(s), there isn’t much consumers can do about it as of yet. Intel has released a detection tool to find out if your system is one of those vulnerable to its effects, with options for a command-line interface and a more consumer-friendly general user interface option. Both highlight what hardware and software your system is running and whether you may be vulnerable to this newly discovered flaw.

If you know or suspect you are affected, the best advice Intel is offering, for now, is to keep an eye on your motherboard or system manufacturer’s website and update your drivers and firmware as and when you can. Lenovo is expected to get an update out by November 23. Dell has confirmed that some 100 of its systems are affected by this bug, though it hasn’t given a time frame for when its firmware update will be released.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Intel Core i9 CPUs are about to get hit with a downgrade, report says
Intel's 14900K CPU socketed in a motherboard.

High-end Intel CPUs are about to lose some significant performance, according to a new report from BenchLife (via VideoCardz). The outlet claims Intel has sent guidance to motherboard partners to implement the Intel Default Settings on Z790 motherboards, following a wave of reports of instability on recent high-end Intel CPUs.

According to the report, these default settings will enforce a PL2 of 188 watts. Intel maintains power limits (PL) for its processors. PL1 is the base power, or the power that the processor can sustain for long periods of time. PL2 is the maximum boost power, which the processor can hit for brief spurts when under a heavy load.

Read more
What to do if your Intel CPU keeps crashing
Pins on Core i9-12900K.

Despite being among the best processors you can buy, some high-end Intel CPUs have faced a wave of instability over the past few months. Intel is investigating the problem, but the company and its motherboard partners have already worked toward some temporary fixes to improve stability on high-end Intel CPUs -- even if it comes at a performance cost.

Before getting into the fixes, keep in mind that they are temporary. Intel will release a statement on the instability soon, likely with more direct guidance on what affected users should do. In addition, the scope of the problem isn't clear -- if you're not experiencing issues, you shouldn't have anything to worry about.
Who's affected

Read more
Intel’s big bet on efficient GPUs might actually work
An Intel Meteor Lake processor socketed in a motherboard.

Intel has a lot riding on its next-gen Battlemage graphics architecture, and a very early benchmark shows some promising signs for performance. An Intel Lunar Lake CPU packing a low-power integrated Battlemage GPU was reportedly spotted in the SiSoftware benchmark database. It boasts not only higher performance than Intel's Meteor Lake chips, but also much better efficiency.

User @miktdt on X (formerly Twitter) spotted the result, which appears to come from an early qualification sample of the HP Spectre x360 14. The benchmark picked up that the laptop was using a Lunar Lake CPU, which is said to come with the Xe2-LPG architecture, a lower-power version of Battlemage.

Read more