Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Intel warns of major flaw in driver update software
iTnews ^ | Jan 21 2016 9:00AM (AUS) | Allie Coyne

Posted on 01/20/2016 7:33:51 PM PST by Utilizer

Intel has patched a major flaw in its driver utility tool that could allow attackers to install malware on victim PCs remotely.

The chipmaker has issued a patch advisory for its Driver Update Utility, urging customers to download the new version of the software.

The tool analyses system drivers on a user's computer and reports on and downloads any new drivers that are available.

The flaw - which exists because the software requests new drivers from Intel servers over an unencrypted connection - allows attackers to instigate man-in-the-middle attacks and cause the download of malicious files and software on victim PCs.

Proof of concept exploits of the vulnerability have already been posted online.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: computing; driver; microsoft; patch; windows; windowspinglist
The article does not specifically state this, but a bit of digging reveals that this deals with the 'doze platform

Specifically win ver 7/8/8.1 64-bit.

No word yet if it has or will have an effect on win10.

1 posted on 01/20/2016 7:33:51 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: dayglored

Ping.


2 posted on 01/20/2016 7:34:11 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

From Intel’s site:

The Intel Driver Update Utility supports 32-bit and 64-bit versions of Microsoft Windows Vista*, Windows 7*, Windows 8* and Windows 8.1*, and Windows 10.

If you’re operating system is not supported, visit Intel Download Center to look for available drivers.

https://www-ssl.intel.com/content/www/us/en/support/topics/iduu-faqs.html


3 posted on 01/20/2016 7:40:25 PM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Thanks for posting


4 posted on 01/20/2016 7:48:47 PM PST by Ray76
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ray76

No worries, mate. :) Hope it helps.


5 posted on 01/20/2016 8:00:54 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: rockrr

If this is usually in Program Files, I had to delete it today.
Malwarebytes found a Trojan.Vonteera and AdwCleaner said Driver Update Utility had to go.
Do I need to install the newer version or just leave it out?


6 posted on 01/20/2016 8:49:13 PM PST by philetus (Keep doing what you always do and you'll eventually get what you deserve)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
Intel's Driver Updater MITM vulnerability ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Utilizer for the ping!!

7 posted on 01/21/2016 5:44:13 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Is this something that will come through automatic updating or do we have to go to Intel for this?


8 posted on 01/21/2016 5:49:15 AM PST by Lurkina.n.Learnin (It's a shame enobama truly doesn't care about any of this. Our country, our future, he doesn't care)
[ Post Reply | Private Reply | To 7 | View Replies]

To: philetus

This is one of those “helpful” utilities that periodically compares the manufacturer-specific drivers that are currently installed on your system and compares them with their inventory. It then tells you if there is a new one available. I find them annoying and usually do not install them.

The risk you take is if they come out with a major revision to something like the BIOS (Basic Input/Output System) - the internal utility that tells the operating system where all the hardware resides.

Bottom line - you can live without it.


9 posted on 01/21/2016 5:57:03 AM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Lurkina.n.Learnin

It’s Intel not Microsoft so you’ll need to go to Intel for the updated utility.


10 posted on 01/21/2016 5:57:54 AM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 8 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

11 posted on 01/21/2016 7:02:05 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

If you build your own systems, this isn’t an issue, as most home builders don’t use the “driver update utility.” If, however, you have an OEM system from Dell, HP, Lenovo, etc. you might want to look for an update. This is a particularly nasty vulnerability. We exploited it in our lab with little more than a code change.


12 posted on 01/21/2016 10:48:55 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rockrr
The Intel Driver Update Utility supports 32-bit and 64-bit versions of Microsoft Windows Vista*, Windows 7*, Windows 8* and Windows 8.1*, and Windows 10.

Whew! This XP user dodges the bullet again.

13 posted on 01/21/2016 1:26:40 PM PST by upchuck (Killary is the poster girl for everything wrong with our government. h/t Mister Da)
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson