Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

I tried this Mac music app, and now I wish macOS had it built-in

August 16, 2026

Meta promised to stop creepy AI glasses videos, but they’re still all over Instagram

August 16, 2026

I played around with the Pixel 11 Pro Fold. I think Google finally saw the right focus points

August 16, 2026

Samsung may be going in for the full iOS-esque Liquid Glass look in OneUI 9.5

August 16, 2026

Apple is reportedly looking to expand its smart home lineup with smart displays, cameras, and updated HomePods

August 16, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » Positive Technologies researcher discovers a new exploitation vector for previously known vulnerabilities in Intel processors
What's On

Positive Technologies researcher discovers a new exploitation vector for previously known vulnerabilities in Intel processors

By dailyguardian.aeApril 3, 20253 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Newly discovered flaw in Intel processors could enable attackers to steal sensitive data, breach encrypted files, and bypass DRM protections

PT SWARMexpert Mark Ermolov discovered a new exploitation vector for the vulnerabilities CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2019-0090, and CVE-2021-0146,which Intel has already fixed. Previously, these issues only enabled partial compromise, but this new method can lead to a complete security breach of affected platforms.

The newly discovered approach to exploitation can be applied to attacks on devices equipped with Intel Pentium, Celeron, and Atom processors from the Denverton, Apollo Lake, Gemini Lake, and Gemini Lake Refresh series. Production of these chips has ended, yet they remain in embedded systems, such as automotive electronics, and in ultra-mobile devices, including e-readers and mini-PCs. Intel was notified in accordance with the responsible disclosure policy but rejected the described problem and refused to take measures to eliminate or reduce the threat level.

The main exploitation vector involves supply chain attacks[1]. Attackers can embed spyware at the assembly or repair stage without altering the hardware.

“This approach requires no soldering or any other physical modification,” said Ermolov. “Local access is enough to retrieve the encryption key and inject malicious code into Intel CSME firmware. These implants often slip under the radar of Intel Boot Guard, virtualization-based security (VBS), and antivirus solutions. They can operate unnoticed, capture user data, lock devices, erase or encrypt files, and carry out other destructive actions.”

A secondary risk involves exploiting these formerly patched flaws to bypass DRM[2]safeguards, which can grant unauthorized access to content from various streaming services. The newly identified method also circumvents some Amazon e-reader protections, allowing threat actors to copy data on devices powered by vulnerable Intel Atom processors.

Attackers can also use these tactics to access data on encrypted storage devices like hard drives or SSDs. This approach can target laptops or tablets built on the at-risk processors.

In 2021, Positive Technologies worked with Intel to reduce the danger posed by CVE-2021-0146, which allowed extraction of the platform chipset key. That key is one of the Intel CSME subsystem’s most closely guarded secrets because it underpins the root of trust and generates every working key for data encryption and code integrity. The new exploitation method decrypts the chipset key by bypassing its fuse encryption layer, opening the door to malicious uses.

Mordor Intelligence ranks Intel as a leading chip supplier for IoT solutions. Its Atom E3900 processors, which are affected by the vulnerabilities, appear in devices used by dozens of automotive manufacturers. Organizations looking to maintain ongoing oversight of vulnerabilities can rely on MaxPatrol VM for continuous management. Should a breach occur, platforms like MaxPatrol SIEM can assist in spotting post-exploitation indicators and tracking further actions by attackers.


[1]Attacks on service providers, through third-party companies.

[2] Digital rights management — technical means of copyright protection.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

CM Hypermarkets Opens Fifth UAE Outlet in Ajman’s Jurf

توب ميد» و«ريفاتالايفكومباوندينغ فارمسي» تعلنان شراكة استراتيجية لتعزيز الرعاية الصحية الشخصية في دولة الإمارات

Topmed and Revitalife: A New Era for UAE Healthcare

MAKE THE MOST OF THE FINAL DAYS OF MODESH WORLD 2026

Shevyn Marshall to Represent Holcim UAE and Oman at One Young World Summit 2026

Last call for ‘A Dubai Invite’ following exceptional resident demand

ICAP UAE Chapter Hosts E-Invoicing Boot Camp as UAE Advances Digital Tax Transformation

Where Big Dreams Take Flight: Bawabat Al Sharq Mall Unveils Its 2026 Back-to-School Experience

Union Coop Anchors ‘Back to School 2026’ on Year-Round Fixed Prices, Not Just Seasonal Discounts

Editors Picks

Meta promised to stop creepy AI glasses videos, but they’re still all over Instagram

August 16, 2026

I played around with the Pixel 11 Pro Fold. I think Google finally saw the right focus points

August 16, 2026

Samsung may be going in for the full iOS-esque Liquid Glass look in OneUI 9.5

August 16, 2026

Apple is reportedly looking to expand its smart home lineup with smart displays, cameras, and updated HomePods

August 16, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

Google may have accidentally leaked a new fitness tracker with a display

August 16, 2026

AI companies may be gobbling up old books, and I really hope they aren’t destroying them

August 16, 2026

Claude is getting ambitious with watermarking, and I can smell the problems from a mile away

August 16, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.