Ihe ọghọm dị na chipsets Intel na-enye ohere ka ewepụtara igodo mgbọrọgwụ ikpo okwu

Ndị nyocha sitere na Teknụzụ Dị Mma mara adịghị ike (CVE-2019-0090), nke na-enye ohere, ma ọ bụrụ na ị nwere ike ịnweta ngwa ahụ, wepụ igodo mgbọrọgwụ ikpo okwu (chipset key), nke a na-eji dị ka mgbọrọgwụ ntụkwasị obi mgbe ị na-achọpụta izi ezi nke ihe dị iche iche nke ikpo okwu, gụnyere TPM (Trusted Platform Module) na UEFI firmware.

A na-akpata adịghị ike ahụ site na ahụhụ dị na ngwaike na Intel CSME firmware, nke dị na boot ROM, nke na-egbochi nsogbu ahụ ka edozi ya na ngwaọrụ ejirila. N'ihi ọnụnọ nke windo n'oge mmalite nke Intel CSME (dịka ọmụmaatụ, mgbe ị na-amalite na ọnọdụ ụra), site na iji aka DMA, ọ ga-ekwe omume ide data na ebe nchekwa Intel CSME ma gbanwee tebụl ibe ebe nchekwa Intel CSME ebidolarị ka ọ kwụsị igbu, weghachite igodo ikpo okwu, wee nweta njikwa ọgbọ nke igodo nzuzo maka modul Intel CSME. A na-eme atụmatụ ibipụta nkọwa nke nrigbu nke adịghị ike ahụ ma emechaa.

Na mgbakwunye na ịwepụ igodo ahụ, njehie ahụ na-enye ohere ka emee koodu na ọkwa efu efu Intel CSME (Converged Security and Manageability Engine). Nsogbu a na-emetụta ọtụtụ chipsets Intel ewepụtara n'ime afọ ise gara aga, mana na ọgbọ nke iri nke processors (Ice Point) nsogbu anaghị apụta. Intel bịara mara nsogbu ahụ ihe dị ka otu afọ gara aga wee hapụ ya mmelite firmware, nke, n'agbanyeghị na ha enweghị ike ịgbanwe koodu adịghị ike na ROM, gbalịa igbochi ụzọ nrigbu nwere ike na ọkwa nke modul Intel CSME n'otu n'otu.

Nsonaazụ enwere ike ịnweta isi ihe mgbọrọgwụ nke ikpo okwu gụnyere nkwado maka ngwa ngwa nke Intel CSME components, nbibi nke sistemu ezoro ezo nke dabere na Intel CSME, yana ohere nke imepụta njirimara EPID.NJ nzuzo emelitere) ka ịfefe kọmputa gị dị ka onye ọzọ iji gafere nchedo DRM. Ọ bụrụ na emebie modul CSME n'otu n'otu, Intel enyela ikike ịmegharị igodo emetụtara site na iji usoro SVN (Ndụ Nchekwa). Ọ bụrụ na ịnweta igodo mgbọrọgwụ ikpo okwu, usoro a adịghị arụ ọrụ ebe ọ bụ na a na-eji igodo mgbọrọgwụ ikpo okwu na-emepụta igodo maka izochi ihe mgbochi iguzosi ike n'ezi ihe (ICVB, Integrity Control Value Blob), na-enweta nke, n'aka nke ya, na-enye gị ohere ịnweta. chepụta koodu nke ọ bụla n'ime modul firmware Intel CSME.

Achọpụtara na a na-echekwa igodo mgbọrọgwụ nke ikpo okwu n'ụdị ezoro ezo na maka nkwekọrịta zuru ezu ọ dịkwa mkpa iji chọpụta igodo ngwaike echekwara na SKS ( Nchekwa Igodo echekwara). Igodo a kapịrị ọnụ abụghị ihe pụrụ iche ma bụrụ otu maka ọgbọ ọ bụla nke chipsets Intel. Ebe ọ bụ na ahụhụ ahụ na-enye ohere ka e gbuo koodu n'otu oge tupu egbochie usoro ọgbọ isi na SKS, a na-ebu amụma na n'oge na-adịghị anya ga-ekpebi igodo ngwaike a.

isi: opennet.ru

Tinye a comment