Intel Active Management Technology£¨AMT£©Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-12

Îó²î±àºÅºÍ¼¶±ð

CVE-2018-3628  ¸ß  ³§ÉÌ×ÔÆÀ£º8.1  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE-2018-3629  ¸ß  ³§ÉÌ×ÔÆÀ£º7.5  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE-2018-3632  ÖÐ  ³§ÉÌ×ÔÆÀ£º6.4  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

Ó°Ïì¹æÄ£

ÔÚʹÓÃÓ¢ÌØ¶û´¦Öóͷ£Æ÷µÄPC×°±¸ÉÏÆôÓÃAMTÊÖÒÕ£¬AMT¹Ì¼þ°æ±¾ÔÚ 3.xÖÁ11.x Ö®¼äµÄÎïÁªÍø×°±¸£¬ÊÂÇéÕ¾£¬·þÎñÆ÷»áÊܵ½Ó°Ïì¡£

ÊÜÓ°ÏìCPUÐͺÅÈçÏ£º

?Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?ºÍÓ¢ÌØ¶û?Ѹ³Û?2²©Èñ?

?1ÖÁ8´úÓ¢ÌØ¶ûî£?´¦Öóͷ£Æ÷¼Ò×å

?Ó¢ÌØ¶û?ÖÁÇ¿?´¦Öóͷ£Æ÷E3-1200 v5ºÍv6²úƷϵÁУ¨Greenlow£©

?Ó¢ÌØ¶û?ÖÁÇ¿?´¦Öóͷ£Æ÷¿ÉÀ©Õ¹ÏµÁУ¨Purley£©

?Ó¢ÌØ¶û?ÖÁÇ¿?´¦Öóͷ£Æ÷WϵÁУ¨Basin Falls£©

Îó²î¸ÅÊö

7ÔÂ10ÈÕ£¬Ó¢Ìضû¹«Ë¾¶ÔIntel Active Management Technology£¨intel  AMT£©¾ÙÐиüУ¬ÐÞ²¹3¸ö²¹¶¡£¬±àºÅΪ£ºCVE-2018-3628£¬CVE-2018-3629£¬CVE-2018-3632¡£

Intel AMTÆäÈ«³ÆÎªIntel Active Management Technology(Ó¢ÌØ¶û×Ô¶¯ÖÎÀíÊÖÒÕ)£¬ËüÊÇÒ»ÖÖ¼¯³ÉÔÚоƬÖеÄϵͳ£¬²»ÒÀÀµÌض¨µÄ²Ù×÷ϵͳ£¬ÕâÒ²ÊÇIntel AMTÓëÔ¶³Ì¿ØÖÆÈí¼þ×î´óµÄ²î±ð¡£×ÝÈ»ÅÌËã»úÊôÓڹرÕ״̬£¬»òÕß²Ù×÷ϵͳ¹ÊÕÏ£¬Í¨¹ý´ËÊÖÒÕ¶¼¿ÉÒÔ¾ÙÐÐÔ¶³ÌÖÎÀí¡£

CVE-2018-3628

ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄHttp´¦Öóͷ£³ÌÐòÖб£´æ»º³åÇøÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄHTTPÇëÇóÀ´Ìᳫ¹¥»÷£¬´Ó¶ø¿ØÖƾÖÓòÍøÖб£´æÎó²îµÄ»úе£¬À´Ö´ÐжñÒâ´úÂë¡£

ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x

CVE-2018-3629

ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄEvent´¦Öóͷ£³ÌÐòÖб£´æ»º³åÇøÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâ´úÂëÀ´Ê¹Ä¿µÄ»úÔì³É¾Ü¾ø·þÎñ¡£

ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x

CVE-2018-3632

ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖÐÉϵÄAMTÄ£¿éÖб£´æÄÚ´æÆÆËðÎó²î£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâ´úÂëÀ´¾ÙÐÐÍâµØ´úÂëÌáȨ¡£

ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º

6.x/7.x/8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20

 

ÐÞ¸´½¨Ò飺

½¨ÒéÓû§¾¡¿ì¸üй̼þµ½×îа汾¡£

 


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

 

Ó¢ÌØ¶ûÌåÏÖ²»ÔÙÖ§³ÖÒÔϲúÆ·µÄÓ¢ÌØ¶û?CSME¹Ì¼þ¡£Ã»ÓжÔÒÔÏÂϵÁÐCPUÌṩ¹Ì¼þ¸üУº

Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?.

Ó¢ÌØ¶û?Ѹ³Û?2²©Èñ?.

µÚÒ»´úÓ¢ÌØ¶û?¿áî£?.

µÚ¶þ´úÓ¢ÌØ¶û?¿áî£?.

µÚÈý´úÓ¢ÌØ¶û?¿áî£?¡£

 

²Î¿¼Á´½Ó£º

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html