CVE-2017-5689
published 2017-05-02CVE-2017-5689: An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel…
PriorityP194critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-28
Exploited in the wild
EPSS
92.19%
99.8th percentile
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hpe | proliant_ml10_gen9_server_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | active_management_technology_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | small_business_technology_firmware | — | — |
| intel | small_business_technology_firmware | — | — |
| siemens | simatic_field_pg_m3_firmware | < 6.2.61.3535 | 6.2.61.3535 |
| siemens | simatic_field_pg_m4_firmware | < 18.01.06 | 18.01.06 |
| siemens | simatic_field_pg_m5_firmware | < 22.01.03 | 22.01.03 |
| siemens | simatic_ipc427e_firmware | < 21.01.05 | 21.01.05 |
Detection & IOCsextracted from sources · hover to see the quote
- →Nessus plugin #97999 actively confirms CVE-2017-5689 by performing the authentication bypass against a provisioned AMT service. ↗
- →Nessus plugin #97998 detects vulnerable AMT versions via the service banner on port 16992; note it may produce false negatives due to banner granularity. ↗
- →Nessus plugin #97997 (credentialed) detects affected Intel AMT systems and provides remediation guidance. ↗
- →PVS/Nessus Network Monitor plugin #6955 detects hosts with AMT running passively. ↗
- →Nessus plugin #105778 detects Intel AMT remote access enabled by inspecting the banner of the service on port 16992. ↗
- →Nessus plugin #102992 identifies systems potentially at risk for AMT-related vulnerabilities without requiring a new scan. ↗
- →Network scanners (SYN and TCP) must be used in addition to local scanner, as the Intel AMT ports are not visible to the OS and cannot be enumerated locally. ↗
- →Scan policy must explicitly probe ports 16992, 16993, and 623 beyond default ports to detect AMT exposure. ↗
- →Block or disable ports 16992–16995 at the network perimeter to mitigate exploitation of CVE-2017-5689. ↗
- ·The Intel AMT ports (16992, 16993, etc.) are not visible to the host OS; local port enumeration will miss them. Network-based SYN/TCP scanners must be used. ↗
- ·For SecurityCenter, the keyword 'default' must be removed from the scan template when specifying AMT ports, otherwise data will not be collected properly. ↗
- ·Banner-based detection (plugin #97998) may produce false negatives because banner versions are not always granular enough to distinguish all vulnerable versions. ↗
- ·The vulnerability only affects systems where AMT has been explicitly enabled; it does not impact all Intel chipsets and has greater impact on servers than consumer PCs. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2c6r-gxwp-v69j: Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2017-5698 [CRITICAL] GHSA-2c6r-gxwp-v69j: Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11
Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.
GHSA
GHSA-v6j9-wwcx-4984: An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and In
ghsa_unreviewed·2022-05-13
CVE-2017-5689 [CRITICAL] CWE-269 GHSA-v6j9-wwcx-4984: An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and In
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
VulnCheck
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
vulncheck·2017·CVSS 9.8
CVE-2017-5689 [CRITICAL] Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Intel products contain a vulnerability which can allow attackers to perform privilege escalation.
Affected: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability
Required Action: Apply updates per vendor instructions.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/063f844548ff; https://vulncheck.com/xdb/6d5963dde233; https://vulncheck.com/xdb/8f2f831b16a0
Remediation Due: 2022-07-28
CISA
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
cisa·2022-01-28·CVSS 9.8
CVE-2017-5689 [CRITICAL] Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Vulnerability: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Affected: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability
Intel products contain a vulnerability which can allow attackers to perform privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-5689
Remediation Due Date: 2022-07-28
CISA ICS
Siemens SIMATIC Industrial PCs, SINUMERIK Panel Control Unit, and SIMOTION P320 (Update A)
cisa_ics·2017-06-29
Siemens SIMATIC Industrial PCs, SINUMERIK Panel Control Unit, and SIMOTION P320 (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC Industrial PCs, SINUMERIK Panel Control Unit, and SIMOTION P320 (Update A)
Last RevisedJuly 11, 2017
Alert CodeICSA-17-180-01A
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Siemens
Equipment: SIMATIC Industrial PCs, SINUMERIK Panel Control Unit (PCU), SIMOTION P320
Vulnerability: Permissions, Privileges, and Access Controls
## UPDATED INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-17-180-01 Siemens Industrial Products using Intel Processors that was published June 29, 2017, on the NC
Cisco
Intel Active Management Technology Privilege Escalation Vulnerability
vendor_cisco·2017-05-12
CVE-2017-5689 CWE-264 Intel Active Management Technology Privilege Escalation Vulnerability
Intel Active Management Technology Privilege Escalation Vulnerability
On May 1st, 2017, Intel released a security advisory titled Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Escalation of Privilege, also known as INTEL-SA-00075. The advisory details a vulnerability in the Intel Active Management (AMT), Intel Small Business (ISB), and Intel Standard Manageability (ISM) firmware modules included with some Intel-based platforms.
The Cisco PSIRT Team has investigated the impact of this vulnerability on Cisco products and determined that no Cisco products are affected.
Additional Information
Additional information about the vulnerability can be found at the following links:
Intel Security Advisory: Intel Active Management Technology
Cisco
Intel Active Management Technology Privilege Escalation Vulnerability
vendor_cisco
CVE-2017-5689 Intel Active Management Technology Privilege Escalation Vulnerability
CVE-2017-5689: Intel Active Management Technology Privilege Escalation Vulnerability
On May 1st, 2017, Intel released a security advisory titled Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Escalation of Privilege , also known as INTEL-SA-00075 . The advisory
CWE: CWE-264, CWE-264
Suricata
ET EXPLOIT Intel AMT Login Attempt Detected (CVE 2017-5689)
suricata·2017-05-10
CVE-2017-5689 ET EXPLOIT Intel AMT Login Attempt Detected (CVE 2017-5689)
ET EXPLOIT Intel AMT Login Attempt Detected (CVE 2017-5689)
Rule: alert http any any -> $HOME_NET [16992,16993,623,664] (msg:"ET EXPLOIT Intel AMT Login Attempt Detected (CVE 2017-5689)"; flow:established,to_server; http.request_header; header_lowercase; content:"authorization|3a 20|Digest"; content:"username=|22|"; content:"response="; fast_pattern; pcre:"/^\s*\x22{2}/R"; reference:url,mjg59.dreamwidth.org/48429.html; reference:url,www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability; reference:cve,2017-5689; classtype:attempted-admin; sid:2024287; rev:5; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2017_05_10, cve CVE_2017_5689, deployment Internal, performance_impact Moderate, signature_severity Major, updated_a
Exploit-DB
Intel Active Management Technology - System Privileges
exploitdb·2017-05-10·CVSS 9.8
CVE-2017-5689 [CRITICAL] Intel Active Management Technology - System Privileges
Intel Active Management Technology - System Privileges
---
#!/usr/bin/python
# -*- coding: utf-8 -*-
# Author: Nixawk
# CVE-2017-5689 = {
# dork="Server: Intel(R) Active Management Technology" port:"16992",
# ports=[
# 623,
# 664,
# 16992,
# 16993,
# 16994,
# 16995
# ]
# products=[
# Active Management Technology (AMT),
# Intel Standard Manageability (ISM),
# Intel Small Business Technology (SBT)
# ]
# version=[
# 6.x,
# 7.x,
# 8.x,
# 9.x,
# 10.x,
# 11.0,
# 11.5,
# 11.6
# ]
import functools
import requests
import logging
import uuid
logging.basicConfig(level=logging.INFO, format="%(message)s")
log = logging.getLogger(__file__)
TIMEOUT = 8
def handle_exception(func):
functools.wraps(func)
def wrapper(*args, **kwds):
try:
return func(*args, **kwds)
except Exception as err:
log.error
Metasploit
Intel AMT Digest Authentication Bypass Scanner
metasploit·CVSS 9.8
CVE-2017-5689 [CRITICAL] Intel AMT Digest Authentication Bypass Scanner
Intel AMT Digest Authentication Bypass Scanner
This module scans for Intel Active Management Technology endpoints and attempts to bypass authentication using a blank HTTP digest (CVE-2017-5689). This service can be found on ports 16992, 16993 (tls), 623, and 624 (tls).
Nuclei
Intel Active Management - Authentication Bypass
nuclei·CVSS 9.8
CVE-2017-5689 [CRITICAL] Intel Active Management - Authentication Bypass
Intel Active Management - Authentication Bypass
Intel Active Management platforms are susceptible to authentication bypass. A non-privileged network attacker can gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability. A non-privileged local attacker can provision manageability features, gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology. The issue has been observed in versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 for all three platforms. Versions before 6 and after 11.6 are not impacted.
Template:
id: CVE-2017-5689
info:
name: Intel Active Management - Authentic
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Tenable
Intel AMT Back in the News
blogs_tenable·2018-01-12·CVSS 9.8
[CRITICAL] Intel AMT Back in the News
Blog / Research
Subscribe
# Intel AMT Back in the News
Scott Caveza
January 12, 2018
4 Min Read
The release of new research from F-Secure spells more trouble for Intel’s Active Management Technology (AMT). AMT is used for remote access monitoring and maintenance in corporate environments. Previously, in 2017, researchers discovered a critical vulnerability with AMT that made headlines. The previous vulnerability was a wide-reaching privilege escalation vulnerability (INTEL-SA-00075, CVE-2017-5689). Now, AMT is in the news again this week, as another serious security issue has been disclosed. The issue was discovered by a security researcher with the Finnish security company F-Secure. It could allow an attacker who has physical access to an affected device to enable the technology’s re
Tenable
Intel AMT Back in the News
blogs_tenable·2018-01-12
Intel AMT Back in the News
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Mitigating an Intel Management Engine Vulnerability
blogs_trendmicro·2017-11-22·CVSS 9.8
CVE-2017-5689 [CRITICAL] Mitigating an Intel Management Engine Vulnerability
Ausnutzung von Schwachstellen
## Mitigating an Intel Management Engine Vulnerability
Intel released a security advisory detailing several flaws in its Management Engine (ME). There is also one notable vulnerability that can pose a big risk, especially to corporate computers and networks:CVE-2017-5689, a privilege escalation flaw.
By: Vit Sembera Nov 22, 2017 Read time: ( words)
Save to Folio
Intel recently released a security advisory detailing several security flaws in its Management Engine (ME). The advisory provides critical ME, Trusted Execution Technology (TXE), and Server Platform Services (SPS) firmware updates for versions 8.X-11.X covering multiple CVE IDs, with CVSS scores between 6.7 and 8.2.
But there is also another notable vulnerability that can pose a bigger risk espec
Trendmicro
Mitigating an Intel Management Engine Vulnerability
blogs_trendmicro·2017-11-22·CVSS 9.8
CVE-2017-5689 [CRITICAL] Mitigating an Intel Management Engine Vulnerability
Exploits & Vulnerabilities
## Mitigating an Intel Management Engine Vulnerability
Intel released a security advisory detailing several flaws in its Management Engine (ME). There is also one notable vulnerability that can pose a big risk, especially to corporate computers and networks:CVE-2017-5689, a privilege escalation flaw.
By: Vit Sembera Nov 22, 2017 Read time: ( words)
Save to Folio
Intel recently released a security advisory detailing several security flaws in its Management Engine (ME). The advisory provides critical ME, Trusted Execution Technology (TXE), and Server Platform Services (SPS) firmware updates for versions 8.X-11.X covering multiple CVE IDs, with CVSS scores between 6.7 and 8.2.
But there is also another notable vulnerability that can pose a bigger risk especial
Trendmicro
Mitigating an Intel Management Engine Vulnerability
blogs_trendmicro·2017-11-22·CVSS 9.8
CVE-2017-5689 [CRITICAL] Mitigating an Intel Management Engine Vulnerability
Exploits y vulnerabilidades
## Mitigating an Intel Management Engine Vulnerability
Intel released a security advisory detailing several flaws in its Management Engine (ME). There is also one notable vulnerability that can pose a big risk, especially to corporate computers and networks:CVE-2017-5689, a privilege escalation flaw.
By: Vit Sembera Nov 22, 2017 Read time: ( words)
Save to Folio
Intel recently released a security advisory detailing several security flaws in its Management Engine (ME). The advisory provides critical ME, Trusted Execution Technology (TXE), and Server Platform Services (SPS) firmware updates for versions 8.X-11.X covering multiple CVE IDs, with CVSS scores between 6.7 and 8.2.
But there is also another notable vulnerability that can pose a bigger risk especia
Trendmicro
Mitigating an Intel Management Engine Vulnerability
blogs_trendmicro·2017-11-22·CVSS 9.8
CVE-2017-5689 [CRITICAL] Mitigating an Intel Management Engine Vulnerability
Sfruttamento vulnerabilità
## Mitigating an Intel Management Engine Vulnerability
Intel released a security advisory detailing several flaws in its Management Engine (ME). There is also one notable vulnerability that can pose a big risk, especially to corporate computers and networks:CVE-2017-5689, a privilege escalation flaw.
By: Vit Sembera Nov 22, 2017 Read time: ( words)
Save to Folio
Intel recently released a security advisory detailing several security flaws in its Management Engine (ME). The advisory provides critical ME, Trusted Execution Technology (TXE), and Server Platform Services (SPS) firmware updates for versions 8.X-11.X covering multiple CVE IDs, with CVSS scores between 6.7 and 8.2.
But there is also another notable vulnerability that can pose a bigger risk especial
Trendmicro
Mitigating an Intel Management Engine Vulnerability
blogs_trendmicro·2017-11-22·CVSS 9.8
CVE-2017-5689 [CRITICAL] Mitigating an Intel Management Engine Vulnerability
Exploits & Vulnerabilities
## Mitigating an Intel Management Engine Vulnerability
Intel released a security advisory detailing several flaws in its Management Engine (ME). There is also one notable vulnerability that can pose a big risk, especially to corporate computers and networks:CVE-2017-5689, a privilege escalation flaw.
By: Vit Sembera 2017/11/22 Read time: ( words)
Save to Folio
Intel recently released a security advisory detailing several security flaws in its Management Engine (ME). The advisory provides critical ME, Trusted Execution Technology (TXE), and Server Platform Services (SPS) firmware updates for versions 8.X-11.X covering multiple CVE IDs, with CVSS scores between 6.7 and 8.2.
But there is also another notable vulnerability that can pose a bigger risk especially
Trendmicro
Mitigating an Intel Management Engine Vulnerability
blogs_trendmicro·2017-11-22·CVSS 9.8
CVE-2017-5689 [CRITICAL] Mitigating an Intel Management Engine Vulnerability
Exploits & Vulnerabilities
# Mitigating an Intel Management Engine Vulnerability
Intel released a security advisory detailing several flaws in its Management Engine (ME). There is also one notable vulnerability that can pose a big risk, especially to corporate computers and networks:CVE-2017-5689, a privilege escalation flaw.
By: Vit Sembera
2017/11/22
Read time: ( words)
Save to Folio
Intel recently released a security advisory detailing several security flaws in its Management Engine (ME). The advisory provides critical ME, Trusted Execution Technology (TXE), and Server Platform Services (SPS) firmware updates for versions 8.X-11.X covering multiple CVE IDs, with CVSS scores between 6.7 and 8.2.
But there is also another notable vulnerability that can pose a bigger risk especially
Checkpoint
2017-5-8 Global Cyber Attack Reports
blogs_checkpoint·2017-05-08
CVE-2017-5689 2017-5-8 Global Cyber Attack Reports
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2017-5-8 Global Cyber Attack Reports
TOP ATTACKS AND BREACHES
A new phishing campaign has hit Gmail users. In the attack, malicious emails with a request to access a
Google Doc were received by victims. Once entered, a fake Google Docs application asked for permissions to victims’ Gmail accounts, and then sent similar phishing emails to his/her contacts. The attack was blocked by Google within an hour after the first reports of it. A day after the attack, a Twitter account was used to take responsibility over it
Tenable
Intel AMT Vulnerability Detection with Nessus and PVS (INTEL-SA-00075)
blogs_tenable·2017-05-04
Intel AMT Vulnerability Detection with Nessus and PVS (INTEL-SA-00075)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Intel AMT Vulnerability Detection with Nessus and PVS (INTEL-SA-00075)
blogs_tenable·2017-05-04
Intel AMT Vulnerability Detection with Nessus and PVS (INTEL-SA-00075)
Blog / News and Views
Subscribe
# Intel AMT Vulnerability Detection with Nessus and PVS (INTEL-SA-00075)
Cris Thomas
May 4, 2017
5 Min Read
Intel recently announced an escalation of privilege vulnerability in the Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology firmware, versions 6 through 11.6. This vulnerability has the potential of being a proverbial big one. The vulnerability has been part of the Intel chipsets for years, specifically the Management Engine (ME). The ME runs things like DRM (Digital Rights Management) and does TPM (Trusted Platform Modules) checks as well as AMT. AMT enables systems administrators to re-image bare metal machines over a remote connection. To accomplish that, the AMT requires many pr
Greynoiseio
NoiseLetter December 2025
blogs_greynoiseio·CVSS 10.0
[CRITICAL] NoiseLetter December 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/98269http://www.securitytracker.com/id/1038385https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdfhttps://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_ushttps://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-frhttps://security.netapp.com/advisory/ntap-20170509-0001/https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdfhttps://www.embedi.com/news/mythbusters-cve-2017-5689https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerabilityhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/98269http://www.securitytracker.com/id/1038385https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdfhttps://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_ushttps://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-frhttps://security.netapp.com/advisory/ntap-20170509-0001/https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdfhttps://www.embedi.com/news/mythbusters-cve-2017-5689https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerabilityhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5689
2017-05-02
Published
2022-01-28
Added to CISA KEV
Exploited in the wild