Interesting that the ME region can be even partially overwritten and will still let the system boot, albeit with an error (guessing a checksum mismatch)...
The Management Engine, think of it as running at Ring -1. It can access hardware below the level of the processor. Injecting malware into it would be the holy grail for attackers, it would be impossible for anything running on the CPU to detect it and the malware would have access to all of the low level hardware. It can even intercept or create packets on the network interfaces.
Luckily the implementation is obscure so it has perfect security, right? There's no way such a complex piece of software that has had very little oversight could have exploitable bugs that would completely destroy any security foundations you have on your machine.
My next question is (and it's probably mentioned further in the thread or manual somewhere): how does the ME chipset route traffic to the Internet in the first place? Piggyback off the OS? Does this mean it's directly coupled with the networking devices on the system somehow? Presumably it will work with any OS....
but it still needs and IP address right? Does ME does its own DHCP/BOOTP configuration or does it rely on some other protocol specific to Intel NICs/Intel infrastructure?
The AMT component must be specifically configured with network information. It is usually kept on a different interface from that used by the OS for security reasons.
What are the odds that it was put there at their request, or partially specified by them? After all, the clipper chip never went anywhere, but neither did the desire.