Intel Active Management Technology£¨AMT£©Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-12Îó²î±àºÅºÍ¼¶±ð
CVE-2018-3628 ¸ß ³§ÉÌ×ÔÆÀ£º8.1 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-3629 ¸ß ³§ÉÌ×ÔÆÀ£º7.5 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-3632 ÖÐ ³§ÉÌ×ÔÆÀ£º6.4 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÔÚʹÓÃÓ¢ÌØ¶û´¦Öóͷ£Æ÷µÄPC×°±¸ÉÏÆôÓÃAMTÊÖÒÕ£¬AMT¹Ì¼þ°æ±¾ÔÚ 3.xÖÁ11.x Ö®¼äµÄÎïÁªÍø×°±¸£¬ÊÂÇéÕ¾£¬·þÎñÆ÷»áÊܵ½Ó°Ïì¡£
ÊÜÓ°ÏìCPUÐͺÅÈçÏ£º
?Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?ºÍÓ¢ÌØ¶û?Ѹ³Û?2²©Èñ?
?1ÖÁ8´úÓ¢ÌØ¶ûî£?´¦Öóͷ£Æ÷¼Ò×å
?Ó¢ÌØ¶û?ÖÁÇ¿?´¦Öóͷ£Æ÷E3-1200 v5ºÍv6²úƷϵÁУ¨Greenlow£©
?Ó¢ÌØ¶û?ÖÁÇ¿?´¦Öóͷ£Æ÷¿ÉÀ©Õ¹ÏµÁУ¨Purley£©
?Ó¢ÌØ¶û?ÖÁÇ¿?´¦Öóͷ£Æ÷WϵÁУ¨Basin Falls£©
Îó²î¸ÅÊö
7ÔÂ10ÈÕ£¬Ó¢Ìضû¹«Ë¾¶ÔIntel Active Management Technology£¨intel AMT£©¾ÙÐиüУ¬ÐÞ²¹3¸ö²¹¶¡£¬±àºÅΪ£ºCVE-2018-3628£¬CVE-2018-3629£¬CVE-2018-3632¡£
Intel AMTÆäÈ«³ÆÎªIntel Active Management Technology(Ó¢ÌØ¶û×Ô¶¯ÖÎÀíÊÖÒÕ)£¬ËüÊÇÒ»ÖÖ¼¯³ÉÔÚоƬÖеÄϵͳ£¬²»ÒÀÀµÌض¨µÄ²Ù×÷ϵͳ£¬ÕâÒ²ÊÇIntel AMTÓëÔ¶³Ì¿ØÖÆÈí¼þ×î´óµÄ²î±ð¡£×ÝÈ»ÅÌËã»úÊôÓڹرÕ״̬£¬»òÕß²Ù×÷ϵͳ¹ÊÕÏ£¬Í¨¹ý´ËÊÖÒÕ¶¼¿ÉÒÔ¾ÙÐÐÔ¶³ÌÖÎÀí¡£
CVE-2018-3628
ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄHttp´¦Öóͷ£³ÌÐòÖб£´æ»º³åÇøÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄHTTPÇëÇóÀ´Ìᳫ¹¥»÷£¬´Ó¶ø¿ØÖƾÖÓòÍøÖб£´æÎó²îµÄ»úе£¬À´Ö´ÐжñÒâ´úÂë¡£
ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x
CVE-2018-3629
ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖеÄAMTÄ£¿éµÄEvent´¦Öóͷ£³ÌÐòÖб£´æ»º³åÇøÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâ´úÂëÀ´Ê¹Ä¿µÄ»úÔì³É¾Ü¾ø·þÎñ¡£
ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º3.xÖÁ11.x
CVE-2018-3632
ÔÚÓ¢ÌØ¶ûConverged Security Manageability Engine£¨CSME£©¹Ì¼þÖÐÉϵÄAMTÄ£¿éÖб£´æÄÚ´æÆÆËðÎó²î£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâ´úÂëÀ´¾ÙÐÐÍâµØ´úÂëÌáȨ¡£
ÊÜÓ°Ïì¹Ì¼þ°æ±¾£º
6.x/7.x/8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20
ÐÞ¸´½¨Ò飺
½¨ÒéÓû§¾¡¿ì¸üй̼þµ½×îа汾¡£
Ó¢ÌØ¶ûÌåÏÖ²»ÔÙÖ§³ÖÒÔϲúÆ·µÄÓ¢ÌØ¶û?CSME¹Ì¼þ¡£Ã»ÓжÔÒÔÏÂϵÁÐCPUÌṩ¹Ì¼þ¸üУº
Ó¢ÌØ¶û?¿áî£?2Ë«ºËvPro?.
Ó¢ÌØ¶û?Ѹ³Û?2²©Èñ?.
µÚÒ»´úÓ¢ÌØ¶û?¿áî£?.
µÚ¶þ´úÓ¢ÌØ¶û?¿áî£?.
µÚÈý´úÓ¢ÌØ¶û?¿áî£?¡£
²Î¿¼Á´½Ó£º
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html


¾©¹«Íø°²±¸11010802024551ºÅ