CVE-2019-0090General(intel / converged_security_and_management_engine)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch intel converged_security_and_management_engine systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • converged_security_and_management_engine
  • server_platform_services

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
converged_security_and_management_engineserver_platform_services

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-08: 1Mentions · 2026-08-11: 1Mentions · 2026-09-18: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 104-0808-1109-18
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-08-111
General1
2026-09-181
General1
Full discourse3 posts
  • XQ55@XQ55
    Disclosure

    يا حياتي تقدر تشغله على أجهزة أقدم أنت ببساطة في خطر أمني لأجهزة قبل الجيل ال 11 أما عن الشكل الطبيعي الذي تقصده النظام يعمل لا أكثر وفوق المواصفات بالحد الأدنى المذكور بكثير راجع CVE-2019-0090 مرفق »» تتمثل الثغرة الأمنية الجوهرية التي تفتقر لحل جذري في معالجات إنتل ما قبل الجيل الحادي عشر في خلل داخل **محرك الإدارة والأمن المدمج (Intel CSME)**، وهي موثقة دوليا تحت الرمز **CVE-2019-0090**. تكمن الأزمة في أن الخلل يقع في **ذاكرة القراءة فقط (Boot ROM)** الخاصة بالمعالج، وهي مكون مادي "صلب" لا يمكن تعديل شفرته البرمجية بعد التصنيع. ### تفاصيل الخطورة الأمنية * **استخراج مفتاح الجذر:** تتيح الثغرة للمهاجم الذي يمتلك وصولا محليا القدرة على استخراج "مفتاح التشفير الرئيسي" الخاص باللوحة الأم. هذا المفتاح هو حجر الزاوية لكل العمليات الأمنية في الجهاز. * **انهيار جدار الحماية:** بمجرد اختراق هذا المستوى، يفقد النظام قدرته على الوثوق في أي شيء، بما في ذلك تشفير القرص الصلب، والتحقق من إقلاع النظام الآمن **Secure Boot**، وحماية المحتوى الرقمي. * **استحالة الإصلاح:** نظرا لأن الخطأ محفور في "قناع الروم" **Mask ROM**، فإن تحديثات البرامج أو الفيرموير لا يمكنها سد الثغرة، بل تكتفي فقط بوضع عقبات برمجية لتصعيب الاستغلال، لكن الأصل يظل مخترقا. ### الفارق المعماري بدءا من الجيل الحادي عشر **Tiger Lake**، أعادت إنتل تصميم المعمارية الأمنية للعتاد لتلافي هذا النوع من الاختراق، مما جعل الأجيال القديمة (العاشر وما قبله) تعاني من ضعف أمني أبدي في مواجهة الهجمات التي تستهدف الطبقات الدنيا من النظام. ### المصادر العلمية الموثقة تعتمد هذه المعلومات على التقرير التقني التفصيلي الصادر عن شركة **Positive Technologies** بعنوان: > **Intel x86 Root of Trust: Loss of Trust** > والذي أكد أن هذه الثغرة تكسر مفهوم "جذر الثقة" **Root of Trust** في معالجات إنتل التي تم إنتاجها خلال الخمس سنوات السابقة لصدور التقرير، وهو ما دفع الشركة لإصدار التنبيه الأمني **Intel-SA-00213**.

    Post summary

    The post explains the CVE‑2019‑0090 flaw in Intel pre‑11 CPUs, detailing how a boot ROM defect allows extraction of the root key and compromise of Secure Boot, noting that firmware updates cannot patch it and referencing the Intel‑SA‑00213 advisory.

    10175850
    136.9K followersView on X
  • Mooiše@moishe_ee
    General

    @AvdNester CVE-2019-0090 запахло @grok расскажи

    Post summary

    The tweet merely references CVE-2019-0090 without providing any technical details, proof of concept, exploit code, or mitigation information.

    30030409
    886 followersView on X
  • TheDavidTai@TheDavidTai
    General

    @dinodaizovi Depends on how secure the tpm and if it can be patched. I don’t think it’s bad to trust the software to be patched faster than hardware. https://www.secpod.com/learn/expressions-and-povs/intel-csme-cve-2019-0090 https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-06-10-001.html

    Post summary

    The tweet expresses an opinion on TPM patching vs. hardware security and links to Intel CSME CVE-2019-0090 resources and an Intel advisory, but provides no technical details, exploit info, or specific remediation steps in the text itself.

    10011263
    1.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appintelconverged_security_and_management_engine---
Appintelserver_platform_services---

Explore more