October 23, 2017

Disabling the Intel Management Engine

The Intel Management Engine (‘IME’ or ‘ME’) is an out-of-band co-processor integrated in all post-2006 Intel-CPU-based PCs. It has full network and memory access and runs proprietary, signed, closed-source software at ring -2,[1][2][3] independently of the BIOS, main CPU and platform operating system[4][5] — a fact which many regard as an unacceptable security risk (particularly given that at least one remotely exploitable security hole has already been reported[6][7]).

