Intel disclosed CVE-2017-5689 in its manageability firmware, warning that systems using Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT) on firmware versions 6.x through 11.6 could be taken over by an unprivileged attacker. The flaw affected business PCs and some servers with vPro/AMT enabled, allowing abuse of management functions that operate below the operating system through the Intel Management Engine, and in some cases could be reached remotely over the network on provisioned systems. Researcher Maksim Malyutin of Embedi reported the issue to Intel, which tracked it under INTEL-SA-00075 and later referenced broader guidance in INTEL-SA-00086.
Embedi said the bug was widely misunderstood as remote code execution, describing it instead as a severe authentication and privilege-escalation weakness that could still enable stealthy compromise through multiple vectors wherever AMT was enabled. Intel said it had no evidence of active exploitation at disclosure, but remediation depended on OEM-supplied, signed firmware updates rather than a direct Intel patch, raising concern that older or unsupported devices might never be fixed. The disclosure also renewed criticism from the EFF and other security advocates, who argued that the Management Engine’s privileged, hard-to-disable design creates systemic risk when vulnerabilities emerge in this hidden administrative layer.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Intel later published security advisory INTEL-SA-00086, adding another official advisory milestone related to Management Engine security issues. The reference provides no further event details beyond the advisory publication.
The Electronic Frontier Foundation published commentary arguing that Intel's Management Engine poses systemic security risks and that users need a way to disable it, citing the recently disclosed AMT-related vulnerability as evidence of the danger of privileged firmware components.
Embedi released a follow-up article correcting misinformation about the bug, stressing that it was a serious logical vulnerability rather than a remote code execution flaw. The company also noted exploitation could occur through multiple vectors on systems with Intel AMT enabled and highlighted the difficulty of deploying firmware fixes.
Intel disclosed a critical privilege-escalation flaw affecting Intel AMT, ISM, and SBT firmware versions 6 through 11.6, warning that attackers could gain control of manageability features on affected systems. The company said remediation required OEM-distributed firmware updates and that it had no evidence of active exploitation at the time.
Intel said the flaw later tracked as CVE-2017-5689 / INTEL-SA-00075 was reported in March 2017 by Maksim Malyutin of Embedi. Intel requested delayed disclosure of technical details while preparing mitigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
intel.com
Open sourceintel.com
Open sourceeff.org
Open sourcetheregister.co.uk
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.