<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Intel Management Engine</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Intel_Management_Engine"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Intel_Management_Engine rootpage-Intel_Management_Engine skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Intel Management Engine</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p class="mw-empty-elt">
</p>
<p>The <b>Intel Management Engine</b> (<b>ME</b>), also known as the <b>Intel Manageability Engine</b>,<sup id="cite_ref-intelamt_1-0" class="reference"><a href="#cite_note-intelamt-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-intel-amt-me_2-0" class="reference"><a href="#cite_note-intel-amt-me-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> is an autonomous subsystem that has been incorporated in virtually all of <a href="Intel" title="Intel">Intel</a>'s <a href="Central_processing_unit" title="Central processing unit">processor</a> <a href="Chipset" title="Chipset">chipsets</a> since 2008.<sup id="cite_ref-intelamt_1-1" class="reference"><a href="#cite_note-intelamt-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-eff1_4-0" class="reference"><a href="#cite_note-eff1-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> It is located in the <a href="Platform_Controller_Hub" title="Platform Controller Hub">Platform Controller Hub</a> of modern Intel <a href="Motherboards" class="mw-redirect" title="Motherboards">motherboards</a>.
</p><p>The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off. This issue can be mitigated with the deployment of a hardware device which is able to disconnect all connections to <a href="Mains_power" class="mw-redirect" title="Mains power">mains power</a> as well as all internal forms of energy storage. The <a href="Electronic_Frontier_Foundation" title="Electronic Frontier Foundation">Electronic Frontier Foundation</a> and some security researchers have voiced concern that the Management Engine is a <a href="Backdoor_(computing)" title="Backdoor (computing)">backdoor</a>.
</p><p>Intel's main competitor, <a href="AMD" title="AMD">AMD</a>, has incorporated the equivalent <a href="AMD_Secure_Technology" class="mw-redirect" title="AMD Secure Technology">AMD Secure Technology</a> (formally called Platform Security Processor) in virtually all of its post-2013 CPUs.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Difference_from_Intel_AMT">Difference from Intel AMT</h2></div>
<p>The Management Engine is often confused with <a href="Intel_Active_Management_Technology" title="Intel Active Management Technology">Intel AMT</a> (Intel Active Management Technology). AMT runs on the ME, but is only available on processors with <a href="VPro" class="mw-redirect" title="VPro">vPro</a>. AMT gives device owners remote administration of their computer,<sup id="cite_ref-techrepublicME_5-0" class="reference"><a href="#cite_note-techrepublicME-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> such as powering it on or off, and reinstalling the operating system.
</p><p>However, the ME itself has been built into all Intel chipsets since 2008, not only those with AMT. While AMT can be unprovisioned by the owner, there is no official, documented way to disable the ME.
</p>
<div class="mw-heading mw-heading2"><h2 id="Design">Design</h2></div>
<p>The subsystem primarily consists of proprietary firmware running on a separate microprocessor that performs tasks during boot-up, while the computer is running, and while it is asleep.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> As long as the chipset or <a href="System_on_a_chip" title="System on a chip">SoC</a> is supplied with power (via battery or power supply), it continues to run even when the system is turned off.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Intel claims the ME is required to provide full performance.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> Its exact workings<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> are largely undocumented<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> and its code is <a href="Obfuscation_(software)" title="Obfuscation (software)">obfuscated</a> using confidential <a href="Huffman_coding" title="Huffman coding">Huffman tables</a> stored directly in hardware, so the firmware does not contain the information necessary to decode its contents.<sup id="cite_ref-auto1_11-0" class="reference"><a href="#cite_note-auto1-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Hardware">Hardware</h3></div>
<p>Starting with ME 11 (introduced in <a href="Skylake_(microarchitecture)" title="Skylake (microarchitecture)">Skylake</a> CPUs), it is based on the <a href="Intel_Quark" title="Intel Quark">Intel Quark</a> x86-based <a href="32-bit" class="mw-redirect" title="32-bit">32-bit</a> CPU and runs the <a href="MINIX_3" class="mw-redirect" title="MINIX 3">MINIX 3</a> operating system.<sup id="cite_ref-ptsecurity1_12-0" class="reference"><a href="#cite_note-ptsecurity1-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> The ME firmware is stored in a partition of the <a href="Serial_Peripheral_Interface_Bus" class="mw-redirect" title="Serial Peripheral Interface Bus">SPI</a> BIOS Flash, using the Embedded Flash File System (EFFS).<sup id="cite_ref-is_13-0" class="reference"><a href="#cite_note-is-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> Previous versions were based on an <a href="ARC_(processor)" title="ARC (processor)">ARC core</a>, with the Management Engine running the <a href="ThreadX" title="ThreadX">ThreadX</a> <a href="RTOS" class="mw-redirect" title="RTOS">RTOS</a>. Versions 1.x to 5.x of the ME used the ARCTangent-A4 (32-bit only instructions) whereas versions 6.x to 8.x used the newer ARCompact (mixed 32- and <a href="16-bit" class="mw-redirect" title="16-bit">16-bit</a> <a href="Instruction_set_architecture" title="Instruction set architecture">instruction set architecture</a>). Starting with ME 7.1, the ARC processor could also execute signed <a href="Java_applets" class="mw-redirect" title="Java applets">Java applets</a>.
</p><p>The ME has its own MAC and IP address for the <a href="Out-of-band_management" title="Out-of-band management">out-of-band management</a> interface, with direct access to the Ethernet controller; one portion of the Ethernet traffic is diverted to the ME even before reaching the host's operating system, for what support exists in various Ethernet controllers, exported and made configurable via <a href="Management_Component_Transport_Protocol" title="Management Component Transport Protocol">Management Component Transport Protocol</a> (MCTP).<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> The ME also communicates with the host via PCI interface.<sup id="cite_ref-is_13-1" class="reference"><a href="#cite_note-is-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> Under Linux, communication between the host and the ME is done via <style data-mw-deduplicate="TemplateStyles:r886049734">
/* start https://en.wikipedia.org/ */
.mw-parser-output .monospaced{font-family:monospace,monospace}
/* end https://en.wikipedia.org/ */
</style><span class="monospaced">/dev/mei</span> or <span class="monospaced">/dev/mei0</span>.<sup id="cite_ref-meilnx_16-0" class="reference"><a href="#cite_note-meilnx-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-meilnx2_17-0" class="reference"><a href="#cite_note-meilnx2-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</p><p>Until the release of <a href="Nehalem_(microarchitecture)" title="Nehalem (microarchitecture)">Nehalem</a> processors, the ME was usually embedded into the motherboard's <a href="Northbridge_(computing)" title="Northbridge (computing)">northbridge</a>, following the <a href="Memory_Controller_Hub" class="mw-redirect" title="Memory Controller Hub">Memory Controller Hub</a> (MCH) layout.<sup id="cite_ref-quest_18-0" class="reference"><a href="#cite_note-quest-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> With the newer Intel architectures (<a href="Intel_5_Series" title="Intel 5 Series">Intel 5 Series</a> onwards), the ME is integrated into the <a href="Platform_Controller_Hub" title="Platform Controller Hub">Platform Controller Hub</a> (PCH).<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Firmware">Firmware</h3></div>
<p>By Intel's current terminology as of 2017, ME is one of several firmware sets for the Converged Security and Manageability Engine (CSME). Prior to AMT version 11, CSME was called Intel Management Engine BIOS Extension (Intel MEBx).<sup id="cite_ref-intelamt_1-2" class="reference"><a href="#cite_note-intelamt-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>Management Engine (ME) – mainstream chipsets<sup id="cite_ref-supermicrosps_21-0" class="reference"><a href="#cite_note-supermicrosps-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup></li>
<li>Server Platform Services (SPS) – server chipsets and <a href="System_on_a_chip" title="System on a chip">SoCs</a><sup id="cite_ref-intelsps_22-0" class="reference"><a href="#cite_note-intelsps-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-supermicrosps_21-1" class="reference"><a href="#cite_note-supermicrosps-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-xeondsps_23-0" class="reference"><a href="#cite_note-xeondsps-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup></li>
<li>Trusted Execution Engine (TXE) – tablet/embedded/low power<sup id="cite_ref-delltxe_24-0" class="reference"><a href="#cite_note-delltxe-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-inteltxe_25-0" class="reference"><a href="#cite_note-inteltxe-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup></li></ul>
<p>It was also found that the ME firmware version 11 runs <a href="MINIX_3" class="mw-redirect" title="MINIX 3">MINIX 3</a>.<sup id="cite_ref-ptsecurity1_12-1" class="reference"><a href="#cite_note-ptsecurity1-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup> Management of the ME modules for provisioning inside the UEFI is done via a tool called Intel Flash Image Tool (FITC).
</p>
<div class="mw-heading mw-heading4"><h4 id="Modules">Modules</h4></div>
<ul><li><a href="Active_Management_Technology" class="mw-redirect" title="Active Management Technology">Active Management Technology</a> (AMT)<sup id="cite_ref-intel-amt-me_2-1" class="reference"><a href="#cite_note-intel-amt-me-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup></li>
<li>Intel <a href="Boot_Guard" class="mw-redirect" title="Boot Guard">Boot Guard</a> (IBG)<sup id="cite_ref-intel-ppt_27-0" class="reference"><a href="#cite_note-intel-ppt-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup> and <a href="Secure_Boot" class="mw-redirect" title="Secure Boot">Secure Boot</a><sup id="cite_ref-inteltxe_25-1" class="reference"><a href="#cite_note-inteltxe-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Quiet_System_Technology" class="mw-redirect" title="Quiet System Technology">Quiet System Technology</a> (QST), formerly known as Advanced Fan Speed Control (AFSC), which provides support for acoustically optimized fan speed control, and monitoring of temperature, voltage, current and fan speed sensors that are provided in the chipset, CPU and other devices present on the motherboard. Communication with the QST firmware subsystem is documented and available through the official <a href="Software_development_kit" title="Software development kit">software development kit</a> (SDK).<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup></li>
<li>Protected Audio Video Path, enforces <a href="HDCP" class="mw-redirect" title="HDCP">HDCP</a><sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-auto1_11-1" class="reference"><a href="#cite_note-auto1-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup></li>
<li>Intel Anti-Theft Technology (AT), discontinued in 2015<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Serial_over_LAN" title="Serial over LAN">Serial over LAN</a> (SOL)<sup id="cite_ref-intel-sol_32-0" class="reference"><a href="#cite_note-intel-sol-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup></li>
<li>Intel Platform Trust Technology (PTT), a firmware-based <a href="Trusted_Platform_Module" title="Trusted Platform Module">Trusted Platform Module</a> (TPM)<sup id="cite_ref-intel-ppt_27-1" class="reference"><a href="#cite_note-intel-ppt-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Near_Field_Communication" class="mw-redirect" title="Near Field Communication">Near Field Communication</a>, a middleware for NFC readers and vendors to access NFC cards and provide secure element access, found in later MEI versions.<sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Security_vulnerabilities">Security vulnerabilities</h2></div>
<p>Several weaknesses have been found in the ME. On May 1, 2017, Intel confirmed a Remote Elevation of Privilege bug (SA-00075) in its Management Technology.<sup id="cite_ref-intelmay_35-0" class="reference"><a href="#cite_note-intelmay-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup> Every Intel platform with provisioned Intel Standard Manageability, Active Management Technology, or Small Business Technology, from <a href="Intel_Nehalem" class="mw-redirect" title="Intel Nehalem">Nehalem</a> in 2008 to <a href="Intel_Kaby_Lake" class="mw-redirect" title="Intel Kaby Lake">Kaby Lake</a> in 2017 has a remotely exploitable security hole in the ME.<sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-reg-2017-05-01_37-0" class="reference"><a href="#cite_note-reg-2017-05-01-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup> Several ways to disable the ME without authorization that could allow ME's functions to be sabotaged have been found.<sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-39" class="reference"><a href="#cite_note-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-ptsecurity1_12-2" class="reference"><a href="#cite_note-ptsecurity1-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> Additional major security flaws in the ME affecting a very large number of computers incorporating ME, Trusted Execution Engine (TXE), and Server Platform Services (SPS) firmware, from <a href="Intel_Skylake" class="mw-redirect" title="Intel Skylake">Skylake</a> in 2015 to <a href="Coffee_Lake" title="Coffee Lake">Coffee Lake</a> in 2017, were confirmed by Intel on 20 November 2017 (SA-00086).<sup id="cite_ref-extreme1_40-0" class="reference"><a href="#cite_note-extreme1-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup> Unlike SA-00075, this bug is even present if AMT is absent, not provisioned or if the ME was "disabled" by any of the known unofficial methods.<sup id="cite_ref-auto2_42-0" class="reference"><a href="#cite_note-auto2-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup> In July 2018, another set of vulnerabilities was disclosed (SA-00112).<sup id="cite_ref-SA-00112_43-0" class="reference"><a href="#cite_note-SA-00112-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup> In September 2018, yet another vulnerability was published (SA-00125).<sup id="cite_ref-44" class="reference"><a href="#cite_note-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Ring_−3_rootkit">Ring −3 rootkit</h3></div>
<p>A <a href="Protection_ring" title="Protection ring">ring</a> −3 rootkit was demonstrated by Invisible Things Lab for the Q35 chipset; it does not work for the later Q45 chipset as Intel implemented additional protections.<sup id="cite_ref-45" class="reference"><a href="#cite_note-45"><span class="cite-bracket">[</span>45<span class="cite-bracket">]</span></a></sup> The exploit worked by remapping the normally protected memory region (top 16 MB of RAM) reserved for the ME. The ME rootkit could be installed regardless of whether the AMT is present or enabled on the system, as the chipset always contains the ARC ME coprocessor. (The "−3" designation was chosen because the ME coprocessor works even when the system is in the <a href="Sleep_mode" title="Sleep mode">S3 state</a>. Thus, it was considered a layer below the <a href="System_Management_Mode" title="System Management Mode">System Management Mode</a> rootkits.<sup id="cite_ref-quest_18-1" class="reference"><a href="#cite_note-quest-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>) For the vulnerable Q35 chipset, a <a href="Keystroke_logger" class="mw-redirect" title="Keystroke logger">keystroke logger</a> ME-based rootkit was demonstrated by Patrick Stewin.<sup id="cite_ref-46" class="reference"><a href="#cite_note-46"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-47" class="reference"><a href="#cite_note-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Zero-touch_provisioning">Zero-touch provisioning</h3></div>
<p>Another security evaluation by Vassilios Ververis showed serious weaknesses in the GM45 chipset implementation. In particular, it criticized AMT for transmitting unencrypted passwords in the SMB provisioning mode when the IDE redirection and Serial over LAN features are used. It also found that the "zero touch" provisioning mode (ZTC) is still enabled even when the AMT appears to be disabled in BIOS. For about 60 euros, Ververis purchased from <a href="GoDaddy" title="GoDaddy">GoDaddy</a> a certificate that is accepted by the ME firmware and allows remote <a href="Zero-touch_provisioning" title="Zero-touch provisioning">"zero touch" provisioning</a> of (possibly unsuspecting) machines, which broadcast their HELLO packets to would-be configuration servers.<sup id="cite_ref-48" class="reference"><a href="#cite_note-48"><span class="cite-bracket">[</span>48<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="SA-00075_(a.k.a._Silent_Bob_is_Silent)">SA-00075 (a.k.a. Silent Bob is Silent)</h3></div>
<p>In May 2017, Intel confirmed that many computers with AMT have had an unpatched critical privilege escalation vulnerability (<a href="CVE-2017-5689" class="mw-redirect" title="CVE-2017-5689">CVE-2017-5689</a>).<sup id="cite_ref-reg-2017-05-01_37-1" class="reference"><a href="#cite_note-reg-2017-05-01-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-49" class="reference"><a href="#cite_note-49"><span class="cite-bracket">[</span>49<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-intelmay_35-1" class="reference"><a href="#cite_note-intelmay-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-50" class="reference"><a href="#cite_note-50"><span class="cite-bracket">[</span>50<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-51" class="reference"><a href="#cite_note-51"><span class="cite-bracket">[</span>51<span class="cite-bracket">]</span></a></sup> The vulnerability was nicknamed "Silent Bob is Silent" by the researchers who had reported it to Intel.<sup id="cite_ref-ssh-com_52-0" class="reference"><a href="#cite_note-ssh-com-52"><span class="cite-bracket">[</span>52<span class="cite-bracket">]</span></a></sup> It affects numerous laptops, desktops and servers sold by <a href="Dell" title="Dell">Dell</a>, <a href="Fujitsu" title="Fujitsu">Fujitsu</a>, <a href="Hewlett-Packard" title="Hewlett-Packard">Hewlett-Packard</a> (later <a href="Hewlett_Packard_Enterprise" title="Hewlett Packard Enterprise">Hewlett Packard Enterprise</a> and <a href="HP_Inc." title="HP Inc.">HP Inc.</a>), Intel, <a href="Lenovo" title="Lenovo">Lenovo</a>, and possibly others.<sup id="cite_ref-ssh-com_52-1" class="reference"><a href="#cite_note-ssh-com-52"><span class="cite-bracket">[</span>52<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-53" class="reference"><a href="#cite_note-53"><span class="cite-bracket">[</span>53<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-54" class="reference"><a href="#cite_note-54"><span class="cite-bracket">[</span>54<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-55" class="reference"><a href="#cite_note-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-56" class="reference"><a href="#cite_note-56"><span class="cite-bracket">[</span>56<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-57" class="reference"><a href="#cite_note-57"><span class="cite-bracket">[</span>57<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-58" class="reference"><a href="#cite_note-58"><span class="cite-bracket">[</span>58<span class="cite-bracket">]</span></a></sup> Those researchers claimed that the bug affects systems made in 2010 or later.<sup id="cite_ref-59" class="reference"><a href="#cite_note-59"><span class="cite-bracket">[</span>59<span class="cite-bracket">]</span></a></sup> Other reports claimed the bug also affects systems made as long ago as 2008.<sup id="cite_ref-60" class="reference"><a href="#cite_note-60"><span class="cite-bracket">[</span>60<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-reg-2017-05-01_37-2" class="reference"><a href="#cite_note-reg-2017-05-01-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup> The vulnerability was described as giving remote attackers:
</p>
<style data-mw-deduplicate="TemplateStyles:r1244412712">
/* start https://en.wikipedia.org/ */
.mw-parser-output .templatequote{overflow:hidden;margin:1em 0;padding:0 32px}.mw-parser-output .templatequotecite{line-height:1.5em;text-align:left;margin-top:0}@media(min-width:500px){.mw-parser-output .templatequotecite{padding-left:1.6em}}
/* end https://en.wikipedia.org/ */
</style><blockquote class="templatequote"><p>"full control of affected machines, including the ability to read and modify everything. It can be used to install persistent malware (possibly in firmware), and read and modify any data."</p></blockquote><div class="templatequotecite"><p style="display: inline; padding-left: 2.3em;">— Tatu Ylönen, <i>ssh.com</i><sup id="cite_ref-ssh-com_52-2" class="reference"><a href="#cite_note-ssh-com-52"><span class="cite-bracket">[</span>52<span class="cite-bracket">]</span></a></sup></p></div>
<div class="mw-heading mw-heading3"><h3 id="PLATINUM">PLATINUM</h3></div>
<p>In June 2017, the <a href="PLATINUM_(cybercrime_group)" title="PLATINUM (cybercrime group)">PLATINUM</a> cybercrime group became notable for exploiting the <a href="Serial_over_LAN" title="Serial over LAN">serial over LAN (SOL)</a> capabilities of AMT to perform data exfiltration of stolen documents.<sup id="cite_ref-61" class="reference"><a href="#cite_note-61"><span class="cite-bracket">[</span>61<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-62" class="reference"><a href="#cite_note-62"><span class="cite-bracket">[</span>62<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-microsoft.com_63-0" class="reference"><a href="#cite_note-microsoft.com-63"><span class="cite-bracket">[</span>63<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-64" class="reference"><a href="#cite_note-64"><span class="cite-bracket">[</span>64<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-65" class="reference"><a href="#cite_note-65"><span class="cite-bracket">[</span>65<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-66" class="reference"><a href="#cite_note-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-67" class="reference"><a href="#cite_note-67"><span class="cite-bracket">[</span>67<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-68" class="reference"><a href="#cite_note-68"><span class="cite-bracket">[</span>68<span class="cite-bracket">]</span></a></sup> SOL is disabled by default and must be enabled to exploit this vulnerability.<sup id="cite_ref-69" class="reference"><a href="#cite_note-69"><span class="cite-bracket">[</span>69<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="SA-00086">SA-00086</h3></div>
<p>Some months after the previous bugs, and subsequent warnings from the EFF,<sup id="cite_ref-eff1_4-1" class="reference"><a href="#cite_note-eff1-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> security firm Positive Technologies claimed to have developed a working <a href="Exploit_(computer_security)" title="Exploit (computer security)">exploit</a>.<sup id="cite_ref-70" class="reference"><a href="#cite_note-70"><span class="cite-bracket">[</span>70<span class="cite-bracket">]</span></a></sup> On 20 November 2017, Intel confirmed that a number of serious flaws had been found in the Management Engine (mainstream), Trusted Execution Engine (tablet/mobile), and Server Platform Services (high end server) firmware, and released a "critical firmware update".<sup id="cite_ref-intel2_71-0" class="reference"><a href="#cite_note-intel2-71"><span class="cite-bracket">[</span>71<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-wired1_72-0" class="reference"><a href="#cite_note-wired1-72"><span class="cite-bracket">[</span>72<span class="cite-bracket">]</span></a></sup> Essentially, every Intel-based computer for the last several years, including most desktops and servers, were found to be vulnerable to having their security compromised, although all the potential routes of exploitation were not entirely known.<sup id="cite_ref-wired1_72-1" class="reference"><a href="#cite_note-wired1-72"><span class="cite-bracket">[</span>72<span class="cite-bracket">]</span></a></sup> It is not possible to patch the problems from the operating system, and a firmware (UEFI, BIOS) update to the motherboard is required, which was anticipated to take quite some time for the many individual manufacturers to accomplish, if it ever would be for many systems.<sup id="cite_ref-extreme1_40-1" class="reference"><a href="#cite_note-extreme1-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading4"><h4 id="Affected_systems">Affected systems</h4></div>
<p>Source:<sup id="cite_ref-intel2_71-1" class="reference"><a href="#cite_note-intel2-71"><span class="cite-bracket">[</span>71<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li><a href="Intel_Atom" title="Intel Atom">Intel Atom</a> – C3000 family</li>
<li>Intel Atom – Apollo Lake E3900 series</li>
<li><a href="Intel_Celeron" class="mw-redirect" title="Intel Celeron">Intel Celeron</a> – N and J series</li>
<li><a href="Intel_Core" title="Intel Core">Intel Core</a> (i3, i5, i7, i9) – 1st, 2nd, 3rd, 4th, 5th, 6th, 7th, and 8th generation</li>
<li><a href="Intel_Pentium" class="mw-redirect" title="Intel Pentium">Intel Pentium</a> – Apollo Lake</li>
<li><a href="Intel_Xeon" class="mw-redirect" title="Intel Xeon">Intel Xeon</a> – E3-1200 v5 and v6 product family</li>
<li>Intel Xeon – Scalable family</li>
<li>Intel Xeon – W family</li></ul>
<div class="mw-heading mw-heading4"><h4 id="Mitigation">Mitigation</h4></div>
<p>None of the known unofficial methods to disable the ME prevent exploitation of the vulnerability. A firmware update by the vendor is required. However, those who discovered the vulnerability note that firmware updates are not fully effective either, as an attacker with access to the ME firmware region can simply flash an old, vulnerable version and then exploit the bug.<sup id="cite_ref-auto2_42-1" class="reference"><a href="#cite_note-auto2-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="SA-00112">SA-00112</h3></div>
<p>In July 2018, Intel announced that three vulnerabilities (<a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2018-3628">2018-3628</a>, CVE-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2018-3629">2018-3629</a>, CVE-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2018-3632">2018-3632</a>) had been discovered and that a patch for the CSME firmware would be required. Intel indicated there would be no patch for 3rd generation Core processors or earlier despite chips or their chipsets as far back as Intel Core 2 Duo vPro and Intel Centrino 2 vPro being affected. However, Intel AMT must be enabled and provisioned for the vulnerability to exist.<sup id="cite_ref-SA-00112_43-1" class="reference"><a href="#cite_note-SA-00112-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-73" class="reference"><a href="#cite_note-73"><span class="cite-bracket">[</span>73<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Assertions_that_ME_is_a_backdoor">Assertions that ME is a backdoor</h2></div>
<p>Critics like the <a href="Electronic_Frontier_Foundation" title="Electronic Frontier Foundation">Electronic Frontier Foundation</a> (EFF), <a href="Libreboot" title="Libreboot">Libreboot</a> developers, and security expert Damien Zammit accused the ME of being a <a href="Backdoor_(computing)" title="Backdoor (computing)">backdoor</a> and a privacy concern.<sup id="cite_ref-softpediaME_74-0" class="reference"><a href="#cite_note-softpediaME-74"><span class="cite-bracket">[</span>74<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-eff1_4-2" class="reference"><a href="#cite_note-eff1-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Zammit stresses that the ME has full access to memory (without the owner-controlled CPU cores having any knowledge), and has full access to the TCP/IP stack and can send and receive network packets independently of the operating system, thus bypassing its firewall.<sup id="cite_ref-techrepublicME_5-1" class="reference"><a href="#cite_note-techrepublicME-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>Intel responded by saying, "Intel does not put backdoors in its products, nor do our products give Intel control or access to computing systems without the explicit permission of the end user."<sup id="cite_ref-techrepublicME_5-2" class="reference"><a href="#cite_note-techrepublicME-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> and "Intel does not and will not design backdoors for access into its products. Recent reports claiming otherwise are misinformed and blatantly false. Intel does not participate in any efforts to decrease the security of its technology."<sup id="cite_ref-register_can_disable_75-0" class="reference"><a href="#cite_note-register_can_disable-75"><span class="cite-bracket">[</span>75<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Disabling_the_ME">Disabling the ME</h2></div>
<p>It is normally not possible for the end-user to disable the ME and there is no officially supported method to disable it, but some undocumented methods to do so were discovered.<sup id="cite_ref-extreme1_40-2" class="reference"><a href="#cite_note-extreme1-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup> The ME's security architecture is designed to prevent disabling. Intel considers disabling the ME to be a security vulnerability, as a malware could abuse it to make the computer lose some of the functionality that the typical user expects, such as the ability to play media with <a href="Digital_rights_management" title="Digital rights management">DRM</a>, specifically DRM media that is using <a href="HDCP" class="mw-redirect" title="HDCP">HDCP</a>.<sup id="cite_ref-76" class="reference"><a href="#cite_note-76"><span class="cite-bracket">[</span>76<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-77" class="reference"><a href="#cite_note-77"><span class="cite-bracket">[</span>77<span class="cite-bracket">]</span></a></sup> On the other hand, it is also possible for malicious actors to use the ME to remotely compromise a system.
</p><p>Strictly speaking, none of the known methods can disable the ME completely, since it is required for booting the main CPU. The currently known methods merely make the ME go into abnormal states soon after boot, in which it seems not to have any working functionality. The ME is still physically connected to the system and its microprocessor continues to execute code. <a href="#Commercial_ME_disablement">Some manufacturers</a> like <a href="Purism_(company)" title="Purism (company)">Purism</a> and <a href="System76" title="System76">System76</a> disable the Intel Management Engine.<sup id="cite_ref-78" class="reference"><a href="#cite_note-78"><span class="cite-bracket">[</span>78<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-79" class="reference"><a href="#cite_note-79"><span class="cite-bracket">[</span>79<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Undocumented_methods">Undocumented methods</h3></div>
<div class="mw-heading mw-heading4"><h4 id="Firmware_neutralization">Firmware neutralization</h4></div>
<p>In 2016, the <i>me_cleaner</i> project found that the ME's integrity verification is broken. The ME is supposed to detect that it has been tampered with and, if this is the case, shut down the PC forcibly 30 minutes after system start.<sup id="cite_ref-80" class="reference"><a href="#cite_note-80"><span class="cite-bracket">[</span>80<span class="cite-bracket">]</span></a></sup> This prevents a compromised system from running undetected, yet allows the owner to fix the issue by flashing a valid version of the ME firmware during the grace period. As the project found out, by making unauthorized changes to the ME firmware, it was possible to force it into an abnormal error state that prevented triggering the shutdown even if large parts of the firmware had been overwritten and thus made inoperable.
</p>
<div class="mw-heading mw-heading4"><h4 id=""High_Assurance_Platform"_mode">"High Assurance Platform" mode</h4></div>
<p>In August 2017, Positive Technologies (<a href="Dmitry_Sklyarov" class="mw-redirect" title="Dmitry Sklyarov">Dmitry Sklyarov</a>) published a method to disable the ME via an <a href="Undocumented_feature" title="Undocumented feature">undocumented built-in mode</a>. As Intel has confirmed<sup id="cite_ref-81" class="reference"><a href="#cite_note-81"><span class="cite-bracket">[</span>81<span class="cite-bracket">]</span></a></sup> the ME contains a switch to enable government authorities such as the <a href="National_Security_Agency" title="National Security Agency">NSA</a> to make the ME go into High-Assurance Platform (HAP) mode after boot. This mode disables most of ME's functions,<sup id="cite_ref-register_can_disable_75-1" class="reference"><a href="#cite_note-register_can_disable-75"><span class="cite-bracket">[</span>75<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-auto3_82-0" class="reference"><a href="#cite_note-auto3-82"><span class="cite-bracket">[</span>82<span class="cite-bracket">]</span></a></sup> and was intended to be available only in machines produced for specific purchasers like the US government; however, most machines sold on the retail market can be made to activate the switch.<sup id="cite_ref-auto3_82-1" class="reference"><a href="#cite_note-auto3-82"><span class="cite-bracket">[</span>82<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-83" class="reference"><a href="#cite_note-83"><span class="cite-bracket">[</span>83<span class="cite-bracket">]</span></a></sup> Manipulation of the HAP bit was quickly incorporated into the me_cleaner project.<sup id="cite_ref-84" class="reference"><a href="#cite_note-84"><span class="cite-bracket">[</span>84<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Commercial_ME_disablement">Commercial ME disablement</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style>
<p>From late 2017 on, several laptop vendors announced their intentions to ship laptops with the Intel ME disabled or let the end-users disable it manually:
</p>
<ul><li>Minifree Ltd has provided <a href="Libreboot" title="Libreboot">Libreboot</a> pre-loaded laptops with Intel ME either not present or disabled since at least 2015.<sup id="cite_ref-85" class="reference"><a href="#cite_note-85"><span class="cite-bracket">[</span>85<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-86" class="reference"><a href="#cite_note-86"><span class="cite-bracket">[</span>86<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-87" class="reference"><a href="#cite_note-87"><span class="cite-bracket">[</span>87<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Purism_(company)" title="Purism (company)">Purism</a> previously petitioned Intel to sell processors without the ME, or release its source code, calling it "a threat to users' digital rights".<sup id="cite_ref-88" class="reference"><a href="#cite_note-88"><span class="cite-bracket">[</span>88<span class="cite-bracket">]</span></a></sup> In March 2017, Purism announced that it had neutralized the ME by erasing the majority of the ME code from the flash memory.<sup id="cite_ref-89" class="reference"><a href="#cite_note-89"><span class="cite-bracket">[</span>89<span class="cite-bracket">]</span></a></sup> It further announced in October 2017<sup id="cite_ref-90" class="reference"><a href="#cite_note-90"><span class="cite-bracket">[</span>90<span class="cite-bracket">]</span></a></sup> that new batches of their <a href="Librem" title="Librem">Librem</a> line of laptops running <a href="PureOS" title="PureOS">PureOS</a> will ship with the ME neutralized, and additionally disable most ME operation via the HAP bit. Updates for existing Librem laptops were also announced.</li>
<li>In November, <a href="System76" title="System76">System76</a> announced their plan to disable the ME on their new and recent machines which ship with <a href="Pop!_OS" title="Pop! OS">Pop!_OS</a> via the HAP bit.<sup id="cite_ref-91" class="reference"><a href="#cite_note-91"><span class="cite-bracket">[</span>91<span class="cite-bracket">]</span></a></sup></li>
<li>In December, <a href="Dell" title="Dell">Dell</a> began showing certain laptops on its website that offered the "Systems Management" option "Intel vPro - ME Inoperable, Custom Order" for an additional fee. Dell has not announced or publicly explained the methods used. In response to press requests, Dell stated that those systems had been offered for quite a while, but not for the general public, and had found their way to the website only inadvertently.<sup id="cite_ref-extremedell_92-0" class="reference"><a href="#cite_note-extremedell-92"><span class="cite-bracket">[</span>92<span class="cite-bracket">]</span></a></sup> The laptops are available only by custom order and only to military, government and intelligence agencies.<sup id="cite_ref-93" class="reference"><a href="#cite_note-93"><span class="cite-bracket">[</span>93<span class="cite-bracket">]</span></a></sup> They are specifically designed for covert operations, such as providing a very robust case and a "stealth" operating mode kill switch that disables display, LED lights, speaker, fan and any wireless technology.<sup id="cite_ref-94" class="reference"><a href="#cite_note-94"><span class="cite-bracket">[</span>94<span class="cite-bracket">]</span></a></sup></li>
<li>In March 2018, <a href="Tuxedo_Computers" title="Tuxedo Computers">Tuxedo Computers</a>, a German company which specializes in PCs which run <a href="Linux" title="Linux">Linux kernel-based operating systems</a>, announced an option in the BIOS of their system to disable ME.<sup id="cite_ref-95" class="reference"><a href="#cite_note-95"><span class="cite-bracket">[</span>95<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading3"><h3 id="Effectiveness_against_vulnerabilities">Effectiveness against vulnerabilities</h3></div>
<p>Neither of the two methods to disable the ME discovered so far turned out to be an effective countermeasure against the SA-00086 vulnerability.<sup id="cite_ref-auto2_42-2" class="reference"><a href="#cite_note-auto2-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup> This is because the vulnerability is in an early-loaded ME module that is essential to boot the main CPU.
</p>
<div class="mw-heading mw-heading2"><h2 id="Reactions">Reactions</h2></div>
<div class="mw-heading mw-heading3"><h3 id="By_Google">By Google</h3></div>
<p>As of 2017, Google was attempting to eliminate <a href="Proprietary_software" title="Proprietary software">proprietary</a> firmware from its servers and found that the ME was a hurdle to that.<sup id="cite_ref-extreme1_40-3" class="reference"><a href="#cite_note-extreme1-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="By_AMD_processor_vendors">By AMD processor vendors</h3></div>
<p>Shortly after SA-00086 was patched, vendors for AMD processor mainboards started shipping BIOS updates that allow disabling the <a href="AMD_Platform_Security_Processor" title="AMD Platform Security Processor">AMD Platform Security Processor</a>,<sup id="cite_ref-96" class="reference"><a href="#cite_note-96"><span class="cite-bracket">[</span>96<span class="cite-bracket">]</span></a></sup> a subsystem with a similar function as the ME.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="AMD_Platform_Security_Processor" title="AMD Platform Security Processor">AMD Platform Security Processor</a></li>
<li><a href="ARM_TrustZone" class="mw-redirect" title="ARM TrustZone">ARM TrustZone</a></li>
<li><a href="Intel_AMT_versions" title="Intel AMT versions">Intel AMT versions</a></li>
<li><a href="Intel_vPro" title="Intel vPro">Intel vPro</a></li>
<li><a href="Meltdown_(security_vulnerability)" title="Meltdown (security vulnerability)">Meltdown (security vulnerability)</a></li>
<li><a href="Microsoft_Pluton" class="mw-redirect" title="Microsoft Pluton">Microsoft Pluton</a></li>
<li><a href="Next-Generation_Secure_Computing_Base" title="Next-Generation Secure Computing Base">Next-Generation Secure Computing Base</a></li>
<li><a href="Samsung_Knox" title="Samsung Knox">Samsung Knox</a></li>
<li><a href="Spectre_(security_vulnerability)" title="Spectre (security vulnerability)">Spectre (security vulnerability)</a></li>
<li><a href="Trusted_Computing" title="Trusted Computing">Trusted Computing</a></li>
<li><a href="Trusted_Execution_Technology" title="Trusted Execution Technology">Trusted Execution Technology</a></li>
<li><a href="Trusted_Platform_Module" title="Trusted Platform Module">Trusted Platform Module</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-intelamt-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-intelamt_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intelamt_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-intelamt_1-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFOster2019" class="citation web cs1">Oster, Joseph E. (September 3, 2019). <a rel="nofollow" class="external text" href="https://software.intel.com/en-us/articles/getting-started-with-intel-active-management-technology-amt">"Getting Started with Intel Active Management Technology (Intel AMT)"</a>. Intel<span class="reference-accessdate">. Retrieved <span class="nowrap">September 22,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-intel-amt-me-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-intel-amt-me_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intel-amt-me_2-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1 cs1-prop-unfit"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20190221093441/https://software.intel.com/en-us/blogs/2011/12/14/intelr-amt-and-the-intelr-me/">"Intel AMT and the Intel ME"</a>. Intel. Archived from the original on February 21, 2019.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/support/articles/000005974/software/chipset-software.html">"Frequently Asked Questions for the Intel Management Engine Verification Utility"</a>. <q>Built into many Intel Chipset–based platforms is a small, low-power computer subsystem called the Intel Management Engine (Intel ME).</q></cite></span>
</li>
<li id="cite_note-eff1-4"><span class="mw-cite-backlink">^ <a href="#cite_ref-eff1_4-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-eff1_4-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-eff1_4-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFPortnoyEckersley2017" class="citation web cs1">Portnoy, Erica; Eckersley, Peter (May 8, 2017). <a rel="nofollow" class="external text" href="https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it">"Intel's Management Engine is a security hazard, and users need a way to disable it"</a>. Electronic Frontier Foundation<span class="reference-accessdate">. Retrieved <span class="nowrap">February 21,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-techrepublicME-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-techrepublicME_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-techrepublicME_5-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-techrepublicME_5-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWallen2016" class="citation web cs1">Wallen, Jack (July 1, 2016). <a rel="nofollow" class="external text" href="https://www.techrepublic.com/article/is-the-intel-management-engine-a-backdoor/">"Is the Intel Management Engine a backdoor?"</a>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/support/articles/000005974/software/chipset-software.html">"Frequently Asked Questions for the Intel Management Engine Verification Utility"</a>. <q>The Intel ME performs various tasks while the system is in sleep, during the boot process, and when your system is running.</q></cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.blackhat.com/eu-17/briefings/schedule/#how-to-hack-a-turned-off-computer-or-running-unsigned-code-in-intel-management-engine-8668">"Black Hat Europe 2017"</a>. <i>BlackHat.com</i>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/support/articles/000005974/software/chipset-software.html">"Frequently Asked Questions for the Intel Management Engine Verification Utility"</a>. <q>This subsystem must function correctly to get the most performance and capability from your PC.</q></cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite id="CITEREFHoffman2017" class="citation web cs1">Hoffman, Chris (November 22, 2017). <a rel="nofollow" class="external text" href="https://www.howtogeek.com/334013/intel-management-engine-explained-the-tiny-computer-inside-your-cpu/">"Intel Management Engine, Explained: The Tiny Computer Inside Your CPU"</a>. <i>How-To Geek</i>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFEckersley2017" class="citation web cs1">Eckersley, Erica Portnoy and Peter (May 8, 2017). <a rel="nofollow" class="external text" href="https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it">"Intel's Management Engine is a security hazard, and users need a way to disable it"</a>. <i>Electronic Frontier Foundation</i>.</cite></span>
</li>
<li id="cite_note-auto1-11"><span class="mw-cite-backlink">^ <a href="#cite_ref-auto1_11-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-auto1_11-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://io.netgarage.org/me/">"Intel ME huffman dictionaries - Unhuffme v2.4"</a>. <i>IO.NetGarage.org</i>.</cite></span>
</li>
<li id="cite_note-ptsecurity1-12"><span class="mw-cite-backlink">^ <a href="#cite_ref-ptsecurity1_12-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ptsecurity1_12-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-ptsecurity1_12-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20170828150536/http://blog.ptsecurity.com/2017/08/disabling-intel-me.html">"Positive Technologies Blog: Disabling Intel ME 11 via undocumented mode"</a>. Archived from <a rel="nofollow" class="external text" href="http://blog.ptsecurity.com/2017/08/disabling-intel-me.html">the original</a> on August 28, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">August 30,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-is-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-is_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-is_13-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text">Igor Skochinsky (<a href="Hex-Rays" class="mw-redirect" title="Hex-Rays">Hex-Rays</a>) <a rel="nofollow" class="external text" href="http://2012.ruxconbreakpoint.com/assets/Uploads/bpx/Breakpoint%202012%20Skochinsky.pdf">Rootkit in your laptop</a>, Ruxcon Breakpoint 2012</span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.intel.com/content/dam/www/public/us/en/documents/datasheets/i210-ethernet-controller-datasheet.pdf">"Intel Ethernet Controller I210 Datasheet"</a> <span class="cs1-format">(PDF)</span>. <a href="Intel" title="Intel">Intel</a>. 2013. pp. 1, 15, 52, <span class="nowrap">621–</span>776<span class="reference-accessdate">. Retrieved <span class="nowrap">November 9,</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.intel.com/content/dam/www/public/us/en/documents/product-briefs/ethernet-x540-brief.pdf">"Intel Ethernet Controller X540 Product Brief"</a> <span class="cs1-format">(PDF)</span>. <a href="Intel" title="Intel">Intel</a>. 2012<span class="reference-accessdate">. Retrieved <span class="nowrap">February 26,</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-meilnx-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-meilnx_16-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20141101045709/https://www.kernel.org/doc/Documentation/misc-devices/mei/mei.txt">"Archived copy"</a>. Archived from <a rel="nofollow" class="external text" href="https://www.kernel.org/doc/Documentation/misc-devices/mei/mei.txt">the original</a> on November 1, 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">February 25,</span> 2014</span>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: archived copy as title (link)</span></span>
</li>
<li id="cite_note-meilnx2-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-meilnx2_17-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.kernel.org/doc/html/latest/driver-api/mei/mei.html">"Introduction — The Linux Kernel documentation"</a>. <i>Kernel.org</i>.</cite></span>
</li>
<li id="cite_note-quest-18"><span class="mw-cite-backlink">^ <a href="#cite_ref-quest_18-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-quest_18-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFRutkowska" class="citation web cs1">Rutkowska, Joanna. <a rel="nofollow" class="external text" href="http://invisiblethingslab.com/resources/misc09/Quest%20To%20The%20Core%20%28public%29.pdf">"A Quest to the Core"</a> <span class="cs1-format">(PDF)</span>. <i>Invisiblethingslab.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 25,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20140211075753/http://www.intel.com/content/dam/www/public/us/en/documents/datasheets/celeron-mobile-p4000-u3000-datasheet.pdf">"Archived copy"</a> <span class="cs1-format">(PDF)</span>. Archived from <a rel="nofollow" class="external text" href="http://www.intel.com/content/dam/www/public/us/en/documents/datasheets/celeron-mobile-p4000-u3000-datasheet.pdf">the original</a> <span class="cs1-format">(PDF)</span> on February 11, 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">February 26,</span> 2014</span>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: archived copy as title (link)</span></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://users.nik.uni-obuda.hu/sima/letoltes/magyar/SZA2011_osz/nappali/Platforms-3_E_2011_12_14.ppt">"Platforms II"</a> <span class="cs1-format">(PDF)</span>. <i>Users.nik.uni-obuda.hu</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 25,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-supermicrosps-21"><span class="mw-cite-backlink">^ <a href="#cite_ref-supermicrosps_21-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-supermicrosps_21-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.supermicro.com/manuals/superserver/4U/MNL-1765.pdf">"FatTwin F618R3-FT+ F618R3-FTPT+ User's Manual"</a> <span class="cs1-format">(PDF)</span>. Super Micro. <q>The Manageability Engine, which is an ARC controller embedded in the IOH (I/O Hub), provides Server Platform Services (SPS) to your system. The services provided by SPS are different from those provided by the ME on client platforms.</q></cite></span>
</li>
<li id="cite_note-intelsps-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-intelsps_22-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/processors/xeon/xeon-e3-1200-v6-family-brief.html">"Intel Xeon Processor E3-1200 v6 Product Family Product Brief"</a>. Intel. <q>Intel Server Platform Services (Intel SPS): Designed for managing rack-mount servers, Intel Server Platform Services provides a suite of tools to control and monitor power, thermal, and resource utilization.</q></cite></span>
</li>
<li id="cite_note-xeondsps-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-xeondsps_23-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/dam/www/public/us/en/documents/platform-briefs/xeon-processor-d-platform-brief.pdf">"Intel Xeon Processor D-1500 Product Family"</a> <span class="cs1-format">(PDF)</span>. Intel.</cite></span>
</li>
<li id="cite_note-delltxe-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-delltxe_24-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=K9HM7">"Intel Trusted Execution Engine Driver"</a>. Dell. <q>This package provides the drivers for the Intel Trusted Execution Engine and is supported on Dell Venue 11 Pro 5130 Tablet</q></cite></span>
</li>
<li id="cite_note-inteltxe-25"><span class="mw-cite-backlink">^ <a href="#cite_ref-inteltxe_25-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-inteltxe_25-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://downloadcenter.intel.com/download/24892/Intel-Trusted-Execution-Engine-Driver-for-Intel-NUC-Kit-NUC5CPYH-NUC5PPYH-NUC5PGYH">"Intel Trusted Execution Engine Driver for Intel NUC Kit NUC5CPYH, NUC5PPYH, NUC5PGYH"</a>. Intel. <q>Installs the Intel Trusted Execution Engine (Intel TXE) driver and firmware for Windows 10 and Windows 7*/8.1*, 64-bit. The Intel TXE driver is required for Secure Boot and platform security features.</q></cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.troopers.de/downloads/troopers17/TR17_ME11_Static.pdf">Positive Technologies Blog:The Way of the Static Analysis</a></span>
</li>
<li id="cite_note-intel-ppt-27"><span class="mw-cite-backlink">^ <a href="#cite_ref-intel-ppt_27-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intel-ppt_27-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/dam/www/public/us/en/documents/white-papers/security-technologies-4th-gen-core-retail-paper.pdf">"Intel Hardware-based Security Technologies for Intelligent Retail Devices"</a> <span class="cs1-format">(PDF)</span>. Intel.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://software.intel.com/sites/default/files/af/73/Intel_QST_Programmers_Reference_Manual.pdf">"Intel Quiet System Technology 2.0: Programmer's Reference Manual"</a> <span class="cs1-format">(PDF)</span>. <a href="Intel" title="Intel">Intel</a>. February 2010<span class="reference-accessdate">. Retrieved <span class="nowrap">August 25,</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://proprivacy.com/privacy-news/intel-management-engine">"The Intel Management Engine – a Privacy Nightmare"</a>. <i>ProPrivacy.com</i>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite id="CITEREFSeptember_20122012" class="citation web cs1">September 2012, Patrick Kennedy 21 (September 21, 2012). <a rel="nofollow" class="external text" href="https://www.tomshardware.com/reviews/vpro-anti-theft-small-business-advantage,3259.html">"Intel vPro In 2012, Small Business Advantage, And Anti-Theft Tech"</a>. <i>Tom's Hardware</i>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: numeric names: authors list (link)</span></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20200801222002/https://service.mcafee.com/webcenter/portal/oracle/webcenter/page/scopedMD/s55728c97_466d_4ddb_952d_05484ea932c6/Page29.jspx?wc.contextURL=%2Fspaces%2Fcp&articleId=TS101986&leftWidth=0%25&showFooter=false&showHeader=false&rightWidth=0%25&centerWidth=100%25&_afrLoop=383304777056094#!@@?showFooter=false&_afrLoop=383304777056094&articleId=TS101986&leftWidth=0%2525&showHeader=false&wc.contextURL=%252Fspaces%252Fcp&rightWidth=0%2525&centerWidth=100%2525&_adf.ctrl-state=o56hl18tm_9">"McAfee KB - End of Life for McAfee/Intel Anti-Theft (TS101986)"</a>. <i>service.mcafee.com</i>. Archived from <a rel="nofollow" class="external text" href="https://service.mcafee.com/webcenter/portal/oracle/webcenter/page/scopedMD/s55728c97_466d_4ddb_952d_05484ea932c6/Page29.jspx?wc.contextURL=%2Fspaces%2Fcp&articleId=TS101986&leftWidth=0%25&showFooter=false&showHeader=false&rightWidth=0%25&centerWidth=100%25&_afrLoop=383304777056094#!@@?showFooter=false&_afrLoop=383304777056094&articleId=TS101986&leftWidth=0%2525&showHeader=false&wc.contextURL=%252Fspaces%252Fcp&rightWidth=0%2525&centerWidth=100%2525&_adf.ctrl-state=o56hl18tm_9">the original</a> on August 1, 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">September 10,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-intel-sol-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-intel-sol_32-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://software.intel.com/en-us/articles/using-intel-amt-serial-over-lan-to-the-fullest">"Using Intel AMT serial-over-LAN to the fullest"</a>. Intel.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.legitreviews.com/how-to-enable-bitlocker-with-intel-ptt-and-no-tpm-for-better-security_211713">"How To Enable BitLocker With Intel PTT and No TPM For Better Security"</a>. <i>Legit Reviews</i>. May 8, 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">September 8,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.kernel.org/doc/html/latest/driver-api/mei/nfc.html">"MEI NFC"</a>.</cite></span>
</li>
<li id="cite_note-intelmay-35"><span class="mw-cite-backlink">^ <a href="#cite_ref-intelmay_35-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intelmay_35-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00075.html">"Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Escalation of Privilege"</a>. <i>Intel.com</i>. March 17, 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">September 22,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><cite id="CITEREFCharlie_Demerjian2017" class="citation web cs1">Charlie Demerjian (May 1, 2017). <a rel="nofollow" class="external text" href="https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/">"Remote security exploit in all 2008+ Intel platforms"</a>. SemiAccurate<span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-reg-2017-05-01-37"><span class="mw-cite-backlink">^ <a href="#cite_ref-reg-2017-05-01_37-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-reg-2017-05-01_37-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-reg-2017-05-01_37-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulnerability/">"Red alert! Intel patches remote execution hole that's been hidden in chips since 2010"</a>. <i>TheRegister.co.uk</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text"><cite id="CITEREFAlaoui2017" class="citation web cs1">Alaoui, Youness (October 19, 2017). <a rel="nofollow" class="external text" href="https://puri.sm/posts/deep-dive-into-intel-me-disablement/">"Deep dive into Intel Management Engine disablement"</a>.</cite></span>
</li>
<li id="cite_note-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-39">^</a></b></span> <span class="reference-text"><cite id="CITEREFAlaoui2017" class="citation web cs1">Alaoui, Youness (March 9, 2017). <a rel="nofollow" class="external text" href="https://puri.sm/posts/neutralizing-intel-management-engine-on-librem-laptops/">"Neutralizing the Intel Management Engine on Librem Laptops"</a>.</cite></span>
</li>
<li id="cite_note-extreme1-40"><span class="mw-cite-backlink">^ <a href="#cite_ref-extreme1_40-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-extreme1_40-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-extreme1_40-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-extreme1_40-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.extremetech.com/computing/259426-intel-patches-major-flaws-intel-management-engine">"Intel Patches Major Flaws in the Intel Management Engine"</a>. Extreme Tech.</cite></span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text"><cite id="CITEREFClaburn2017" class="citation web cs1">Claburn, Thomas (November 20, 2017). <a rel="nofollow" class="external text" href="https://www.theregister.com/2017/11/20/intel_flags_firmware_flaws/">"Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets"</a>. <i>The Register</i>.</cite></span>
</li>
<li id="cite_note-auto2-42"><span class="mw-cite-backlink">^ <a href="#cite_ref-auto2_42-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-auto2_42-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-auto2_42-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.theregister.com/2017/12/06/intel_management_engine_pwned_by_buffer_overflow/">"Intel Management Engine pwned by buffer overflow"</a>. <i>TheRegister.com</i>.</cite></span>
</li>
<li id="cite_note-SA-00112-43"><span class="mw-cite-backlink">^ <a href="#cite_ref-SA-00112_43-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-SA-00112_43-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html">"INTEL-SA-00112"</a>. <i>Intel</i>.</cite></span>
</li>
<li id="cite_note-44"><span class="mw-cite-backlink"><b><a href="#cite_ref-44">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00125.html">"INTEL-SA-00125"</a>. <i>Intel</i>.</cite></span>
</li>
<li id="cite_note-45"><span class="mw-cite-backlink"><b><a href="#cite_ref-45">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20160412045958/http://invisiblethingslab.com/press/itl-press-2009-03.pdf">"Invisible Things Lab to present two new technical presentations disclosing system-level vulnerabilities affecting modern PC hardware at its core"</a> <span class="cs1-format">(PDF)</span>. <i>Invisiblethingslab.com</i>. Archived from <a rel="nofollow" class="external text" href="http://invisiblethingslab.com/press/itl-press-2009-03.pdf">the original</a> <span class="cs1-format">(PDF)</span> on April 12, 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">May 25,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-46"><span class="mw-cite-backlink"><b><a href="#cite_ref-46">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20160304033404/http://www.stewin.org/slides/pstewin-SPRING6-EvaluatingRing-3Rootkits.pdf">"FG Security in telecommunications : Evaluating "Ring-3" Rootkits"</a> <span class="cs1-format">(PDF)</span>. <i>Stewin.org</i>. Archived from <a rel="nofollow" class="external text" href="http://www.stewin.org/slides/pstewin-SPRING6-EvaluatingRing-3Rootkits.pdf">the original</a> <span class="cs1-format">(PDF)</span> on March 4, 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">May 25,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-47"><span class="mw-cite-backlink"><b><a href="#cite_ref-47">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20160303222145/http://stewin.org/slides/44con_2013-dedicated_hw_malware-stewin_bystrov.pdf">"Persistent, Stealthy Remote-controlled Dedicated Hardware Malware"</a> <span class="cs1-format">(PDF)</span>. <i>Stewin.org</i>. Archived from <a rel="nofollow" class="external text" href="http://stewin.org/slides/44con_2013-dedicated_hw_malware-stewin_bystrov.pdf">the original</a> <span class="cs1-format">(PDF)</span> on March 3, 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">May 25,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-48"><span class="mw-cite-backlink"><b><a href="#cite_ref-48">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://web.it.kth.se/~maguire/DEGREE-PROJECT-REPORTS/100402-Vassilios_Ververis-with-cover.pdf">"Security Evaluation of Intel's Active Management Technology"</a> <span class="cs1-format">(PDF)</span>. <i>Web.it.kth.se</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 25,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-49"><span class="mw-cite-backlink"><b><a href="#cite_ref-49">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20170505125225/http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2017-5689">"CVE - CVE-2017-5689"</a>. <i>Cve.mitre.org</i>. Archived from <a rel="nofollow" class="external text" href="https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2017-5689">the original</a> on May 5, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-50"><span class="mw-cite-backlink"><b><a href="#cite_ref-50">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.darknet.org.uk/2016/06/intel-hidden-management-engine-x86-security-risk/">"Intel Hidden Management Engine - x86 Security Risk?"</a>. Darknet. June 16, 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-51"><span class="mw-cite-backlink"><b><a href="#cite_ref-51">^</a></b></span> <span class="reference-text"><cite id="CITEREFGarrett2017" class="citation web cs1">Garrett, Matthew (May 1, 2017). <a rel="nofollow" class="external text" href="https://mjg59.dreamwidth.org/48429.html">"Intel's remote AMT vulnerablity"</a>. <i>mjg59.dreamwidth.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-ssh-com-52"><span class="mw-cite-backlink">^ <a href="#cite_ref-ssh-com_52-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ssh-com_52-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-ssh-com_52-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20180305001456/https://www.ssh.com/vulnerability/intel-amt/">"2017-05-05 ALERT! Intel AMT EXPLOIT OUT! IT'S BAD! DISABLE AMT NOW!"</a>. <i>Ssh.com\Accessdate=2017-05-07</i>. Archived from <a rel="nofollow" class="external text" href="https://www.ssh.com/vulnerability/intel-amt/">the original</a> on March 5, 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">November 25,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-53"><span class="mw-cite-backlink"><b><a href="#cite_ref-53">^</a></b></span> <span class="reference-text"><cite id="CITEREFDan_Goodin2017" class="citation web cs1">Dan Goodin (May 6, 2017). <a rel="nofollow" class="external text" href="https://arstechnica.com/security/2017/05/the-hijacking-flaw-that-lurked-in-intel-chips-is-worse-than-anyone-thought/">"The Hijacking Flaw That Lurked in Intel Chips Is Worse than Anyone Thought"</a>. Ars Technica<span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-54"><span class="mw-cite-backlink"><b><a href="#cite_ref-54">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20170511075221/http://en.community.dell.com/support-forums/laptop/f/3518/t/20011662">"General: BIOS updates due to Intel AMT IME vulnerability - General Hardware - Laptop - Dell Community"</a>. <i>En.Community.Dell.com</i>. May 2, 2017. Archived from <a rel="nofollow" class="external text" href="http://en.community.dell.com/support-forums/laptop/f/3518/t/20011662">the original</a> on May 11, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-55"><span class="mw-cite-backlink"><b><a href="#cite_ref-55">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://support.ts.fujitsu.com/content/Intel_Firmware.asp">"Advisory note: Intel Firmware vulnerability – Fujitsu Technical Support pages from Fujitsu Fujitsu Continental Europe, Middle East, Africa & India"</a>. Support.ts.fujitsu.com. May 1, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-56"><span class="mw-cite-backlink"><b><a href="#cite_ref-56">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20170508041543/http://h22208.www2.hpe.com/eginfolib/securityalerts/CVE-2017-5689-Intel/CVE-2017-5689.html">"HPE | HPE CS700 2.0 for VMware"</a>. <i>H22208.www2.hpe.com</i>. May 1, 2017. Archived from <a rel="nofollow" class="external text" href="http://h22208.www2.hpe.com/eginfolib/securityalerts/CVE-2017-5689-Intel/CVE-2017-5689.html">the original</a> on May 8, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-57"><span class="mw-cite-backlink"><b><a href="#cite_ref-57">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://communities.intel.com/thread/114071">"Intel Security Advisory regarding escalation o... |Intel Communities"</a>. <i>Communities.Intel.com</i>. May 4, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-58"><span class="mw-cite-backlink"><b><a href="#cite_ref-58">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://support.lenovo.com/us/en/product_security/LEN-14963">"Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Remote Privilege Escalation"</a>. <i>Support.lenovo.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-59"><span class="mw-cite-backlink"><b><a href="#cite_ref-59">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20180817215423/https://embedi.com/news/mythbusters-cve-2017-5689">"MythBusters: CVE-2017-5689"</a>. <i>Embedi.com</i>. May 2, 2017. Archived from <a rel="nofollow" class="external text" href="https://www.embedi.com/news/mythbusters-cve-2017-5689">the original</a> on August 17, 2018.</cite></span>
</li>
<li id="cite_note-60"><span class="mw-cite-backlink"><b><a href="#cite_ref-60">^</a></b></span> <span class="reference-text"><cite id="CITEREFCharlie_Demerjian2017" class="citation web cs1">Charlie Demerjian (May 1, 2017). <a rel="nofollow" class="external text" href="https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/">"Remote security exploit in all 2008+ Intel platforms"</a>. <i>SemiAccurate.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-61"><span class="mw-cite-backlink"><b><a href="#cite_ref-61">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://arstechnica.com/security/2017/06/sneaky-hackers-use-intel-management-tools-to-bypass-windows-firewall/">"Sneaky hackers use Intel management tools to bypass Windows firewall"</a>. June 9, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-62"><span class="mw-cite-backlink"><b><a href="#cite_ref-62">^</a></b></span> <span class="reference-text"><cite id="CITEREFTung" class="citation web cs1">Tung, Liam. <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/windows-firewall-dodged-by-hot-patching-spies-using-intel-amt-says-microsoft/">"Windows firewall dodged by 'hot-patching' spies using Intel AMT, says Microsoft - ZDNet"</a>. <i><a href="ZDNet" class="mw-redirect" title="ZDNet">ZDNet</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-microsoft.com-63"><span class="mw-cite-backlink"><b><a href="#cite_ref-microsoft.com_63-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blogs.technet.microsoft.com/mmpc/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/">"PLATINUM continues to evolve, find ways to maintain invisibility"</a>. June 7, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-64"><span class="mw-cite-backlink"><b><a href="#cite_ref-64">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.bleepingcomputer.com/news/security/malware-uses-obscure-intel-cpu-feature-to-steal-data-and-avoid-firewalls/">"Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-65"><span class="mw-cite-backlink"><b><a href="#cite_ref-65">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.itnews.com.au/news/hackers-abuse-low-level-management-feature-for-invisible-backdoor-464499">"Hackers abuse low-level management feature for invisible backdoor"</a>. <i>iTnews</i><span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-66"><span class="mw-cite-backlink"><b><a href="#cite_ref-66">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.theregister.co.uk/AMP/2017/06/08/vxers_exploit_intels_amt_for_malwareoverlan/">"Vxers exploit Intel's Active Management for malware-over-LAN • The Register"</a>. <i>TheRegister.co.uk</i><span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-67"><span class="mw-cite-backlink"><b><a href="#cite_ref-67">^</a></b></span> <span class="reference-text"><cite id="CITEREFSecurity2017" class="citation web cs1">Security, heise (June 9, 2017). <a rel="nofollow" class="external text" href="https://www.heise.de/security/meldung/Intel-Fernwartung-AMT-bei-Angriffen-auf-PCs-genutzt-3739441.html">"Intel-Fernwartung AMT bei Angriffen auf PCs genutzt"</a>. <i>Security</i><span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-68"><span class="mw-cite-backlink"><b><a href="#cite_ref-68">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://channel9.msdn.com/Shows/Windows-Security-Blog/PLATINUM-activity-group-file-transfer-method-using-Intel-AMT-SOL">"PLATINUM activity group file-transfer method using Intel AMT SOL"</a>. <i>Channel 9</i><span class="reference-accessdate">. Retrieved <span class="nowrap">June 10,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-69"><span class="mw-cite-backlink"><b><a href="#cite_ref-69">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.bleepingcomputer.com/news/security/malware-uses-obscure-intel-cpu-feature-to-steal-data-and-avoid-firewalls/">"Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls"</a>. <i>BleepingComputer</i>.</cite></span>
</li>
<li id="cite_note-70"><span class="mw-cite-backlink"><b><a href="#cite_ref-70">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.blackhat.com/eu-17/briefings/schedule/#how-to-hack-a-turned-off-computer-or-running-unsigned-code-in-intel-management-engine-8668">"Black Hat Europe 2017"</a>. <i>BlackHat.com</i>.</cite></span>
</li>
<li id="cite_note-intel2-71"><span class="mw-cite-backlink">^ <a href="#cite_ref-intel2_71-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intel2_71-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/us/en/support/articles/000025619/software.html">"Intel Management Engine Critical Firmware Update (Intel SA-00086)"</a>. Intel.</cite></span>
</li>
<li id="cite_note-wired1-72"><span class="mw-cite-backlink">^ <a href="#cite_ref-wired1_72-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-wired1_72-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFNewman" class="citation magazine cs1">Newman, Lily Hay. <a rel="nofollow" class="external text" href="https://www.wired.com/story/intel-management-engine-vulnerabilities-pcs-servers-iot/">"Intel Chip Flaws Leave Millions of Devices Exposed"</a>. <i>Wired</i>.</cite></span>
</li>
<li id="cite_note-73"><span class="mw-cite-backlink"><b><a href="#cite_ref-73">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.intel.com/content/www/ca/en/support/articles/000029388/software/chipset-software.html">"Intel Active Management Technology 9.x/10.x/11.x Security Review..."</a> <i>Intel</i>.</cite></span>
</li>
<li id="cite_note-softpediaME-74"><span class="mw-cite-backlink"><b><a href="#cite_ref-softpediaME_74-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFCimpanu2016" class="citation web cs1">Cimpanu, Catalin (June 17, 2016). <a rel="nofollow" class="external text" href="https://news.softpedia.com/news/intel-x86-cpus-come-with-a-secret-backdoor-that-nobody-can-touch-or-disable-505347.shtml">"Intel x86 CPUs Come with a Secret Backdoor That Nobody Can Touch or Disable"</a>. <i>softpedia</i>.</cite></span>
</li>
<li id="cite_note-register_can_disable-75"><span class="mw-cite-backlink">^ <a href="#cite_ref-register_can_disable_75-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-register_can_disable_75-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.theregister.com/2017/08/29/intel_management_engine_can_be_disabled/">"Intel ME controller chip has secret kill switch"</a>. <i>TheRegister.com</i>.</cite></span>
</li>
<li id="cite_note-76"><span class="mw-cite-backlink"><b><a href="#cite_ref-76">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.phoronix.com/news/HDCP-2.2-For-i915-DRM">"HDCP 2.2 Content Protection Being Worked On For The i915 DRM Driver"</a>.</cite></span>
</li>
<li id="cite_note-77"><span class="mw-cite-backlink"><b><a href="#cite_ref-77">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.phoronix.com/news/HDCP-2.2-Intel-Linux-Driver">"HDCP 2.2 Support Updated For The Intel DRM Linux Driver"</a>.</cite></span>
</li>
<li id="cite_note-78"><span class="mw-cite-backlink"><b><a href="#cite_ref-78">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://puri.sm/faq/what-is-intel-management-engine-and-what-are-concerns-with-it-regarding-librem-laptops/">"What is Intel Management Engine and what are concerns with it regarding Librem laptops?"</a>. September 27, 2018.</cite></span>
</li>
<li id="cite_note-79"><span class="mw-cite-backlink"><b><a href="#cite_ref-79">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blog.system76.com/post/major-updates-for-system76-open-firmware-june-2023">"Major Updates for System76 Open Firmware!"</a>. June 2, 2023.</cite></span>
</li>
<li id="cite_note-80"><span class="mw-cite-backlink"><b><a href="#cite_ref-80">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/corna/me_cleaner">"corna/me_cleaner"</a>. September 10, 2020 – via GitHub.</cite></span>
</li>
<li id="cite_note-81"><span class="mw-cite-backlink"><b><a href="#cite_ref-81">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.bleepingcomputer.com/news/hardware/researchers-find-a-way-to-disable-much-hated-intel-me-component-courtesy-of-the-nsa/">"Researchers Find a Way to Disable Much-Hated Intel ME Component Courtesy of the NSA"</a>. <i>BleepingComputer</i>.</cite></span>
</li>
<li id="cite_note-auto3-82"><span class="mw-cite-backlink">^ <a href="#cite_ref-auto3_82-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-auto3_82-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFResearch" class="citation web cs1">Research, Author Positive. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20201201175708/http://blog.ptsecurity.com/2017/08/disabling-intel-me.html?m=1">"Disabling Intel ME 11 via undocumented mode"</a>. Archived from <a rel="nofollow" class="external text" href="http://blog.ptsecurity.com/2017/08/disabling-intel-me.html?m=1">the original</a> on December 1, 2020.</cite> <span class="cs1-visible-error citation-comment"><code class="cs1-code">{{cite web}}</code>: </span><span class="cs1-visible-error citation-comment"><code class="cs1-code">|first=</code> has generic name (help)</span></span>
</li>
<li id="cite_note-83"><span class="mw-cite-backlink"><b><a href="#cite_ref-83">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/corna/me_cleaner">"corna/me_cleaner"</a>. <i>GitHub</i>. March 19, 2022.</cite></span>
</li>
<li id="cite_note-84"><span class="mw-cite-backlink"><b><a href="#cite_ref-84">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/corna/me_cleaner/commit/ced3b46ba2ccd74602b892f9594763ef34671652">"Set the HAP bit (ME >= 11) or the AltMeDisable bit (ME < 11) · corna/me_cleaner@ced3b46"</a>. <i>GitHub</i>.</cite></span>
</li>
<li id="cite_note-85"><span class="mw-cite-backlink"><b><a href="#cite_ref-85">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.fsf.org/news/libreboot-t400-laptop-now-fsf-certified-to-respect-your-freedom">"Libreboot T400 laptop now FSF-certified to respect your freedom — Free Software Foundation — Working together for free software"</a>. <i>www.fsf.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">April 30,</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-86"><span class="mw-cite-backlink"><b><a href="#cite_ref-86">^</a></b></span> <span class="reference-text"><cite id="CITEREFBärwaldt" class="citation web cs1">Bärwaldt, Erik. <a rel="nofollow" class="external text" href="http://www.linux-magazine.com/Issues/2018/210/Free-Firmware-with-Libreboot">"Liberated » Linux Magazine"</a>. <i>Linux Magazine</i><span class="reference-accessdate">. Retrieved <span class="nowrap">April 30,</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-87"><span class="mw-cite-backlink"><b><a href="#cite_ref-87">^</a></b></span> <span class="reference-text"><cite id="CITEREFBiggs2017" class="citation web cs1">Biggs, John (August 11, 2017). <a rel="nofollow" class="external text" href="https://techcrunch.com/2017/08/11/the-minifree-libreboot-t400-is-free-as-in-freedom/">"The Minifree Libreboot T400 is free as in freedom"</a>. <i>TechCrunch</i><span class="reference-accessdate">. Retrieved <span class="nowrap">April 30,</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-88"><span class="mw-cite-backlink"><b><a href="#cite_ref-88">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20160616070449/https://puri.sm/posts/petition-for-intel-to-release-an-me-less-cpu-design/">"Petition for Intel to Release an ME-Less CPU Design"</a>. June 16, 2016. Archived from <a rel="nofollow" class="external text" href="https://puri.sm/posts/petition-for-intel-to-release-an-me-less-cpu-design/">the original</a> on June 16, 2016.</cite></span>
</li>
<li id="cite_note-89"><span class="mw-cite-backlink"><b><a href="#cite_ref-89">^</a></b></span> <span class="reference-text"><cite id="CITEREFAlaoui2017" class="citation web cs1">Alaoui, Youness (March 9, 2017). <a rel="nofollow" class="external text" href="https://puri.sm/posts/neutralizing-intel-management-engine-on-librem-laptops/">"Neutralizing the Intel Management Engine on Librem Laptops"</a>. <i>puri.sm</i><span class="reference-accessdate">. Retrieved <span class="nowrap">December 13,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-90"><span class="mw-cite-backlink"><b><a href="#cite_ref-90">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://puri.sm/posts/purism-librem-laptops-completely-disable-intel-management-engine/">"Purism Librem Laptops Completely Disable Intel's Management Engine"</a>. October 19, 2017.</cite></span>
</li>
<li id="cite_note-91"><span class="mw-cite-backlink"><b><a href="#cite_ref-91">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20200815170940/https://blog.system76.com/post/168050597573/system76-me-firmware-updates-plan">"System76 ME Firmware Updates Plan"</a>. <i>System76 Blog</i>. Archived from <a rel="nofollow" class="external text" href="https://blog.system76.com/post/168050597573/system76-me-firmware-updates-plan">the original</a> on August 15, 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">September 10,</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-extremedell-92"><span class="mw-cite-backlink"><b><a href="#cite_ref-extremedell_92-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.extremetech.com/computing/260219-dell-sells-pcs-without-intel-management-engine-tradeoffs">"Dell Sells PCs without Intel's Management Engine, but with Tradeoffs"</a>. <i>ExtremeTech.com</i>.</cite></span>
</li>
<li id="cite_note-93"><span class="mw-cite-backlink"><b><a href="#cite_ref-93">^</a></b></span> <span class="reference-text"><cite id="CITEREFonline2017" class="citation web cs1 cs1-prop-foreign-lang-source">online, heise (December 6, 2017). <a rel="nofollow" class="external text" href="https://www.heise.de/newsticker/meldung/Dell-schaltet-Intel-Management-Engine-in-Spezial-Notebooks-ab-3909860.html">"Dell schaltet Intel Management Engine in Spezial-Notebooks ab"</a> [Dell switches off Intel Management Engine in special notebooks]. <i>heise online</i> (in German).</cite></span>
</li>
<li id="cite_note-94"><span class="mw-cite-backlink"><b><a href="#cite_ref-94">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.dell.com/support/manuals/us/en/04/latitude-14-5414-laptop/5414_om/stealth-mode?guid=guid-3655713b-6a1b-46a8-ba69-eaa3c324b3cd&lang=en-us">"Dell Latitude 14 Rugged — 5414 Series Owner's Manual"</a>. <i>Dell.com</i>.</cite></span>
</li>
<li id="cite_note-95"><span class="mw-cite-backlink"><b><a href="#cite_ref-95">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.tuxedocomputers.com/de/Infos/News/TUXEDO-deaktiviert-Intels-Management-Engine">"TUXEDO deaktiviert Intels Management Engine - TUXEDO Computers"</a>. <i>www.tuxedocomputers.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">February 7,</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-96"><span class="mw-cite-backlink"><b><a href="#cite_ref-96">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.phoronix.com/scan.php?page=news_item&px=AMD-PSP-Disable-Option">"AMD Reportedly Allows Disabling PSP Secure Processor With Latest AGESA - Phoronix"</a>. <i>Phoronix.com</i>. December 7, 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">April 16,</span> 2019</span>.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://downloadcenter.intel.com/download/27150">Intel® Converged Security and Management Engine Version Detection Tool (Intel® CSMEVDT) (Intel-SA-00086 security vulnerability detection tool)</a> from Intel Download Center</li>
<li><a rel="nofollow" class="external text" href="https://i.blackhat.com/USA-19/Wednesday/us-19-Hasarfaty-Behind-The-Scenes-Of-Intel-Security-And-Manageability-Engine.pdf">Behind the Scenes of Intel Security and Manageability Engine</a> – A presentation by Intel security researchers presented in Black Hat USA 2019</li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Firmware_and_booting244" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="3"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div id="Firmware_and_booting244" style="font-size:114%;margin:0 4em"><a href="Firmware" title="Firmware">Firmware</a> and <a href="Booting" title="Booting">booting</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Processes</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Booting_process_of_Windows" title="Booting process of Windows">Windows</a></span>
<ul><li><span class="nowrap"><a href="Architecture_of_Windows_9x#Boot_sequence" title="Architecture of Windows 9x">9x</a></span></li>
<li><span class="nowrap"><a href="Booting_process_of_Windows_NT" class="mw-redirect" title="Booting process of Windows NT">NT</a></span></li></ul></li>
<li><span class="nowrap"><a href="Booting_process_of_Linux" title="Booting process of Linux">Linux</a></span>
<ul><li><span class="nowrap"><a href="Booting_process_of_Android_devices" title="Booting process of Android devices">Android</a></span></li></ul></li></ul>
</div></td><td class="noviewer navbox-image" rowspan="10" style="width:1px;padding:0 0 0 2px"><div><span typeof="mw:File"></span></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Booting <a href="Firmware#Computers" title="Firmware">firmware</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Types</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Proprietary_firmware" title="Proprietary firmware">Proprietary firmware</a></span></li>
<li><span class="nowrap"><a href="Open-source_firmware" title="Open-source firmware">Open-source firmware</a></span></li>
<li><span class="nowrap"><a href="Custom_firmware" title="Custom firmware">Custom firmware</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Interfaces</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="UEFI" title="UEFI">UEFI</a></span></li>
<li><span class="nowrap"><a href="BIOS" title="BIOS">BIOS</a></span>
<ul><li><span class="nowrap"><a href="Video_BIOS" title="Video BIOS">Video BIOS</a></span></li></ul></li>
<li><span class="nowrap"><a href="Open_Firmware" title="Open Firmware">Open Firmware</a></span></li>
<li><span class="nowrap"><a href="ACPI" title="ACPI">ACPI</a></span></li>
<li><span class="nowrap"><a href="MultiProcessor_Specification" title="MultiProcessor Specification">MultiProcessor Specification</a></span></li>
<li><span class="nowrap"><a href="Advanced_Power_Management" title="Advanced Power Management">APM</a></span></li>
<li><span class="nowrap"><a href="Legacy_Plug_and_Play" title="Legacy Plug and Play">Legacy Plug and Play</a></span></li>
<li><span class="nowrap"><a href="ARC_(specification)" title="ARC (specification)">AlphaBIOS</a></span></li>
<li><span class="nowrap"><a href="SRM_firmware" title="SRM firmware">SRM</a></span></li>
<li><span class="nowrap"><a href="Simple_Firmware_Interface" title="Simple Firmware Interface">SFI</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Implementations</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="SeaBIOS" title="SeaBIOS">SeaBIOS</a></span></li>
<li><span class="nowrap"><a href="Award_Software" title="Award Software">Award BIOS</a></span></li>
<li><span class="nowrap"><a href="American_Megatrends" title="American Megatrends">American Megatrends</a></span>
<ul><li><span class="nowrap"><a href="AMIBIOS" class="mw-redirect" title="AMIBIOS">AMIBIOS</a></span></li>
<li><span class="nowrap"><a href="AMI_Aptio" class="mw-redirect" title="AMI Aptio">AMI Aptio</a></span></li></ul></li>
<li><span class="nowrap"><a href="Insyde_Software" title="Insyde Software">InsydeH2O</a></span></li>
<li><span class="nowrap"><a href="Phoenix_Technologies" title="Phoenix Technologies">Phoenix SecureCore UEFI</a></span></li>
<li><span class="nowrap"><a href="TianoCore_EDK_II" title="TianoCore EDK II">TianoCore EDK II</a></span></li>
<li><span class="nowrap"><a href="OpenBIOS" title="OpenBIOS">OpenBIOS</a></span></li>
<li><span class="nowrap"><a href="Coreboot" title="Coreboot">Coreboot</a></span></li>
<li><span class="nowrap"><a href="Libreboot" title="Libreboot">Libreboot</a></span></li>
<li><span class="nowrap"><a href="LinuxBoot" title="LinuxBoot">LinuxBoot</a></span></li>
<li><span class="nowrap"><a href="Kickstart_(Amiga)" title="Kickstart (Amiga)">Kickstart</a></span></li>
<li><span class="nowrap"><a href="Run-Time_Abstraction_Services" title="Run-Time Abstraction Services">Run-Time Abstraction Services</a></span></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Hybrid firmware bootloader</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Common_Firmware_Environment" title="Common Firmware Environment">Common Firmware Environment</a> </span></li>
<li><span class="nowrap"><a href="Das_U-Boot" title="Das U-Boot">Das U-Boot</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Bootloader" title="Bootloader">Bootloaders</a></th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Bootloader_unlocking" title="Bootloader unlocking">Bootloader unlocking</a></span></li>
<li><span class="nowrap"><a href="Comparison_of_bootloaders" title="Comparison of bootloaders">Comparison of bootloaders</a></span></li></ul>
</div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th id="Implementations15" scope="row" class="navbox-group" style="width:1%">Implementations</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Acronis_OS_Selector" class="mw-redirect" title="Acronis OS Selector">Acronis OS Selector</a></span></li>
<li><span class="nowrap"><a href="Barebox" title="Barebox">Barebox</a></span></li>
<li><span class="nowrap"><a href="BootManager" class="mw-redirect" title="BootManager">BootManager</a></span></li>
<li><span class="nowrap"><a href="BootX_(Apple)" title="BootX (Apple)">BootX (Apple)</a></span></li>
<li><span class="nowrap"><a href="BootX_(Linux)" title="BootX (Linux)">BootX (Linux)</a></span></li>
<li><span class="nowrap"><a href="GNU_GRUB" title="GNU GRUB">GNU GRUB</a></span></li>
<li><span class="nowrap"><a href="IBoot" title="IBoot">iBoot</a></span></li>
<li><span class="nowrap"><a href="Systemd-boot" title="Systemd-boot">systemd-boot</a></span></li>
<li><span class="nowrap"><a href="Limine_(bootloader)" title="Limine (bootloader)">Limine</a></span></li>
<li><span class="nowrap"><a href="Loadlin" title="Loadlin">loadlin</a></span></li>
<li><span class="nowrap"><a href="MILO_(bootloader)" title="MILO (bootloader)">MILO</a></span></li>
<li><span class="nowrap"><a href="NTLDR" title="NTLDR">NTLDR</a></span></li>
<li><span class="nowrap"><a href="OpeniBoot" title="OpeniBoot">OpeniBoot</a></span></li>
<li><span class="nowrap"><a href="Plop_Boot_Manager" title="Plop Boot Manager">Plop Boot Manager</a></span></li>
<li><span class="nowrap"><a href="RedBoot" title="RedBoot">RedBoot</a></span></li>
<li><span class="nowrap"><a href="REFInd" title="REFInd">rEFInd</a></span></li>
<li><span class="nowrap"><a href="REFIt" title="REFIt">rEFIt</a></span></li>
<li><span class="nowrap"><a href="SYSLINUX" title="SYSLINUX">SYSLINUX</a></span></li>
<li><span class="nowrap"><a href="Windows_Boot_Manager" title="Windows Boot Manager">Windows Boot Manager</a></span></li>
<li><span class="nowrap"><a href="XOSL" title="XOSL">xOSL</a></span></li>
<li><span class="nowrap"><a href="Yaboot" title="Yaboot">Yaboot</a></span></li></ul>
</div></td></tr></tbody></table><div>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Partition layouts</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="GUID_Partition_Table" title="GUID Partition Table">GUID Partition Table</a></span></li>
<li><span class="nowrap"><a href="Master_boot_record" title="Master boot record">Master boot record</a></span></li>
<li><span class="nowrap"><a href="Apple_Partition_Map" title="Apple Partition Map">Apple Partition Map</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="System_partition_and_boot_partition" title="System partition and boot partition">Partitions</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="EFI_system_partition" title="EFI system partition">EFI system partition</a></span></li>
<li><span class="nowrap"><a href="BIOS_boot_partition" title="BIOS boot partition">BIOS boot partition</a></span></li>
<li><span class="nowrap"><a href=".//boot/" class="mw-redirect" title="/boot/">/boot/</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Utilities</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Software</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Flashrom_(utility)" title="Flashrom (utility)">flashrom</a></span></li>
<li><span class="nowrap"><a href="Fwupd" title="Fwupd">fwupd</a></span></li>
<li><span class="nowrap"><a href="UEFITool" title="UEFITool">UEFITool</a></span></li>
<li><span class="nowrap"><a href="Odin_(firmware_flashing_software)" title="Odin (firmware flashing software)">Odin</a></span>
<ul><li><span class="nowrap"><a href="Odin_(firmware_flashing_software)#Heimdall" title="Odin (firmware flashing software)">Heimdall</a></span></li></ul></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Hardware</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Bus_Pirate" title="Bus Pirate">Bus Pirate</a></span></li>
<li><span class="nowrap"><a href="Raspberry_Pi" title="Raspberry Pi">Raspberry Pi</a></span></li>
<li><span class="nowrap"><a href="FTDI" title="FTDI">ft2232</a></span></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Network_booting" title="Network booting">Network boot</a></th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Preboot_Execution_Environment" title="Preboot Execution Environment">Preboot Execution Environment</a></span>
<ul><li><span class="nowrap"><a href="GPXE" title="GPXE">gPXE</a></span></li>
<li><span class="nowrap"><a href="IPXE" title="IPXE">iPXE</a></span></li></ul></li>
<li><span class="nowrap"><a href="NetBoot" title="NetBoot">NetBoot</a></span></li>
<li><span class="nowrap"><a href="Remote_Initial_Program_Load" title="Remote Initial Program Load">Remote Initial Program Load</a></span></li>
<li><span class="nowrap"><a href="Wake-on-LAN" title="Wake-on-LAN">Wake-on-LAN</a></span></li>
<li><span class="nowrap"><a href="Wake-on-ring" title="Wake-on-ring">Wake-on-ring</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">ROM variants</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Read-only_memory" title="Read-only memory">ROM</a></span></li>
<li><span class="nowrap"><a href="Programmable_ROM" title="Programmable ROM">PROM</a></span></li>
<li><span class="nowrap"><a href="EPROM" title="EPROM">EPROM</a></span></li>
<li><span class="nowrap"><a href="EEPROM" title="EEPROM">EEPROM</a></span></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Related</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><span class="nowrap"><a href="Boot_ROM" title="Boot ROM">Boot ROM</a></span></li>
<li><span class="nowrap"><a href="ROM_hacking" title="ROM hacking">ROM hacking</a></span></li>
<li><span class="nowrap"><a href="ROM_image" title="ROM image">ROM image</a></span></li>
<li><span class="nowrap"><a href="Execute_in_place" title="Execute in place">Execute in place</a></span></li>
<li><span class="nowrap"><a href="Devicetree" title="Devicetree">Devicetree</a></span></li>
<li><span class="nowrap"><a href="Fastboot" title="Fastboot">Fastboot</a></span></li>
<li><span class="nowrap"><a href="Instant-on" title="Instant-on">Instant-on</a></span></li>
<li><span class="nowrap"><a href="Power-on_self-test" title="Power-on self-test">Power-on self-test</a></span></li>
<li><span class="nowrap"><a href="Qualcomm_EDL_mode" title="Qualcomm EDL mode">EDL mode</a></span></li></ul>
</div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-04-30" href="https://en.wikipedia.org/wiki/?title=Intel_Management_Engine&oldid=1288161181">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>