Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
IntelTXE-PoC — Intel Management Engine JTAG Proof of Concept - 2022 Instructions | Kitploit
Tools/GitHubGitHub/xenokovah/inteltxe-poc
Embedded Systems SecurityPayload GenerationExploitationReverse EngineeringHardware HackingBinary AnalysisFirmware AnalysisBinary Exploitation
GitHubxenokovah/inteltxe-poc

IntelTXE-PoC

Intel Management Engine JTAG Proof of Concept - 2022 Instructions

View Repository
325214 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Disclaimer

All information is provided for educational purposes only. Follow these instructions at your own risk. Neither the authors nor their employer are responsible for any direct or consequential damage or loss arising from any person or organization acting or failing to act on the basis of information contained in this page.

Content

Introduction
Required Software
Generating the Payload
Generating the Unlock Token
Preparing the SPI Flash Image
Integrating Files Into the Firmware Image
Disabling OEM Signing
Building the Firmware Image
BringUP Main CPU
Writing the Image to SPI Flash
Preparing the USB Debug Cable
Patching OpenIPC Configuration Files
Decrypting OpenIPC Configuration Files
Adding LMT Core to the Configuration
Setting the IPC_PATH Environment Variable
Performing an Initial Check of JTAG Operability
Show CPU ME Thread
Halting Cores
ME Debugging: Quick Start
Reading Arbitrary Memory
Reading ROM
Why TXE?
Tested Platforms List
Authors
License

Introduction

Vulnerability INTEL-SA-00086 allows to activate JTAG for Intel Management Engine core. We developed our [JTAG PoC][8] for the Gigabyte Brix GP-BPCE-3350C platform. Although we recommend that would-be researchers use the same platform, other manufacturers' platforms with the Intel Apollo Lake chipset should support the PoC as well (for TXE version 3.0.1.1107).

Because the Gigabyte Brix GP-BPCE-3350C is no longer widely commercially available, these instructions have been updated to instead target the AAEON UP Squared SKU UPS-APLX7-A20-0864 (Intel Atom® x7-E3950). If you purchase this board, make sure to also get the power supply, serial adapter, and any USB-to-serial adapter. Additionally, the UP Squared only needs a basic USB debug cable to perform DCI debugging. The USB debug cable should be connected to the port where the yellow USB cable is shown here.

Required Software

Intel System Tools

Vulnerability INTEL-SA-00086 involves a buffer overflow when handling a file stored on MFS (the [internal ME file system][6]). The full file path is /home/bup/ct. You will need to integrate a vulnerability-exploiting version of this file into the ME firmware by using Intel Flash Image Tool (FIT), one of the Intel System Tools provided by Intel to OEMs of hardware based on Intel PCH chipsets.

The Intel ME (TXE, SPS) System Tools utilities are not intended for end users—so you cannot find them on the official Intel website. However, some OEMs publish them as part of software updates together with device drivers. So, for integrating our PoC you need "CSTXE System Tools v3", which can be found here.

Intel System Studio

You need to install Intel System Studio for performing JTAG debugging. In our original experiments, we used Intel System Studio 2018. These instructions have been updated for Intel System Studio 2020 which can be obtained from here.

Intel TXE Firmware

The PoC targets Intel TXE firmware version 3.0.1.1107. The "CSTXE 3.0" image repository at Win-Raid forums contains the necessary TXE firmware version.

Python

All our scripts are written on Python. We recommend using Python 2.7 Also the scripts require pycrypto packet. To install pycrypto, run the following command:

pip install pycrypto

Performing baseline x86 debugging via DCI

While the purpose of this guide is to enable JTAG debugging in the ME via an exploit, it is a good practice to first sanity check and make sure you can perform normal JTAG debugging of the UP Squared board via DCI. AAEON no longer ships their BIOSes with DCI enabled, as they stated on their forums that this led to instability. (And older versions of the BIOS before v5.0 that had DCI enabled will no longer work with newer hardware, due to a DRAM vendor hardware change.) Therefore, to enable DCI JTAG on the UP Squared, you must perform 3 steps:

  1. Perform the binary patching described by Satoshi Tanda here (although it should say to use UEFITool 0.28 not 2.8).
  2. Enable DCI through the BIOS configuration menu by pressing F7 at boot, entering the default UP password (upassw0rd), from the Main menu, going down to "CRB Setup" -> "CSB Chipset" -> "South Cluster Configuration" -> "Miscellaneous Configuration" -> "DCI Enable (HDCIEN)" and setting it to enabled. Then exit the BIOS setup menu, save the configuration change, and reboot the system.
  3. Open "C:\IntelSWTools\system_studio_2020\system_debugger_2020\target_indicator\bin\TargetIndicator.exe" and confirm that when you have that system plugged in to the UP Squared via the debug cable, that there is displayed a blue indicator that DCI is possible such as the below: DCI Indicator

You can then launch ":\Program Files (x86)\IntelSWTools\sw_dev_tools\system_debugger_2020\system_debug_legacy\xdb.bat", connect to the target, and break into it, and single step to confirm you have baseline debugging capabilities.

(You can also follow the blog series by Alan Sguigna here on how to build the Debug-build of the open source code for this platform, which will be DCI-debuggable from the reset vector. However, note that due to a hardware change for DRAM, this built-from-source code will no longer fully boot on new hardware - it will instead hang at boot time as noted here. Intel TianoCore maintainers have refused to fix this.)

Generating the Payload

Run the script me_exp_bxtp.py:

me_exp_bxtp.py -f <file_name>

The script generates the necessary data and exports it to the specified file (indicate either the full file path or, within the current directory, simply a name, ct.bin by default). This file will be used later by FIT.

Download Tool