A security flaw rooted deep in the silicon of nearly every Intel chip released in the past five years was discovered this week by threat researchers at Positive Technologies.

The vulnerability could allow a local attacker to exploit a known hardware vulnerability in Intel's Converged Security and Management Engine to breach Intel's PCH microchip and gain access to the chipset key used for cryptography. The breach would be impossible to detect and could allow attackers to decrypt data stored on the machine or forge the enhanced privacy ID (EPID).

This is a big deal, writes Positive Technology in a blog post, as EPID is used in digital rights management, financial transactions, and the attestation of IoT devices.

"The vulnerability resembles an error recently identified in the BootROM of Apple mobile platforms but affects only Intel systems. Both vulnerabilities allow extracting users' encrypted data," wrote Mark Ermolov, lead specialist of OS and hardware security at Positive Technologies.

Ermolov says attackers can obtain the key in several ways.

"For example, they can extract it from a lost or stolen laptop in order to decrypt confidential data. Unscrupulous suppliers, contractors, or even employees with physical access to the computer can get hold of the key," he said. "In some cases, attackers can intercept the key remotely, provided they have gained local access to a target PC as part of a multistage attack, or if the manufacturer allows remote firmware updates of internal devices, such as Intel Integrated Sensor Hub."

Intel Downplays Risk, Advises Preventative Steps

In an email to SDxCentral, Intel downplayed the severity of the vulnerability saying it an attacker would require physical access to the device. The chipmaker says it has already issued instructions as to how to limit the risk to end users.

Intel is warning customers to maintain physical possession of their machines and install security patches and firmware updates as they become available, as well as take precautions to prevent intrusions or exploitations.

A spokesperson said the attacks can be mitigated by installing the latest CSME firmware and BIOS updates on affected systems. However, unless the system manufacturer has enabled the Intel CSME Anti-Rollback feature, local attacks may still be possible.

However, Positive Technologies says even with firmware and BIOS updates it is impossible to rule out the possibility of a breach. Instead, the company recommends users disable Intel CSME-based encryption and consider upgrading to 10th-generation Intel CPUs, which are not affected by this vulnerability.

Stamping Out Hype

The vulnerability has quickly garnered considerable attention within the tech community because the security flaw can't be fixed and can only be mitigated. However, exactly how vulnerable users are to this kind of attack remains up for debate.

"As far as this vulnerability goes, it is quite significant, especially for the fact that it can break DRM," wrote Anshel Sag of Moor Research and Insights, in an email to SDxCentral. "That said, it appears that 10th-Gen products are unaffected, and with all of the latest patches people are in agreement that this vulnerability requires physical access to a system. This significantly reduces the probability of an attack, as the vast majority of attacks are accomplished remotely."

However, Sag notes that high-value targets are still vulnerable, and end users should consider disabling CSME, but he admits this may not be an ideal solution.

"The problem is that CSME is fundamental to Intel's cryptography capabilities and if you're doing anything secure you'll need it," he wrote, adding that this latest vulnerability only serves to erode Intel's security story and arm the chipmaker's competitors with new ammunition.

In a blog post, Security Vendor Capsule8 attempted to quell the hype surrounding Intel's latest security fiasco arguing that much of the concern comes from the potential for attackers to exploit secure storage, which it says researchers have yet to do.

"This disclosure itself demonstrates a new evil maid attack for Intel chipsets," it says. "It requires a motivated and resourced attacker with at least (non-trivially obtained) local access — if not physical access — which considerably reduces the probability of widespread exploitation."