ISC StormCast for Tuesday, May 2nd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 May 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 2nd, 2017 edition of the Sands and its Storm Center's Stormcast. |
| 0:07.4 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:11.7 | On Monday, Charlie Dersian did release an interesting vulnerability that affects all recent Intel CPUs that do provide remote |
| 0:23.2 | manageability features. The earliest affected one is the Nehalam platform, which was released |
| 0:31.3 | in 2008, but even the most recent cabby lake processors may be affected the problem here is the |
| 0:41.6 | Intel active management technology also known as Intel small business technology |
| 0:47.8 | or Intel standard manageability technology all of these three technologies are vulnerable and attacks can lead |
| 0:58.0 | to an elevation of privileges. The impact very much depends on whether or not these features |
| 1:04.4 | are configured to be reachable across the network. So typically you find this feature in systems being deployed in |
| 1:13.6 | businesses. You're less likely going to see it in a home system, but then again, there is no clear |
| 1:19.5 | distinction, what's a business system, what's a home system. So I would still double check in a home |
| 1:26.0 | environment whether or not you have this feature enabled. |
| 1:29.6 | If it's only enabled for local access, then what you have is approach escalation vulnerability. |
| 1:35.3 | An attacker that has access to the system can escalate privileges to become an administrator. |
| 1:41.5 | Now, more dangerous if you have it exposed on the network, which is particularly |
| 1:47.8 | common for businesses that would like to have the kind of remote manageability that this feature |
| 1:54.5 | offers. Then your system is exposed on port 16,992 through 16,995. |
| 2:03.6 | Essentially, this feature will intercept all network traffic |
| 2:07.6 | on these ports. |
| 2:08.6 | The traffic will not be passed to the CPU. |
| 2:12.6 | Instead, it will be processed by these management features. |
| 2:16.6 | It's also available over Wi-Fi. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

