As for microcode vulnerabilities, don't be surprised if they start coming down the pipeline. It was only recently that researchers figured out (publicly, at least) how to hack and upload microcode on Intel chips: https://media.ccc.de/v/34c3-9058-everything_you_want_to_know...
> This alternate instruction set includes an extended set of integer, MMX, floating-point, and 3DNow! instructions along with additional registers and some more powerful instruction forms over the x86 instruction architecture.
> This alternate instruction set is intended for testing, debug, and special application usage. Accordingly, it is not documented for general usage. If you have a justified need for access to these instructions, contact your VIA representative.
It then goes on to explain in detail the mechanism for initiating execution of this alternate set of instructions. So while I am sure the researchers put plenty of work in this it seems reading the manual helped a lot more than one would expect for a "backdoor"...
[0] http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemia...
It's still great hacking and fuzzing to find the privilege escalation instruction.
> 15:22, 10 August 2018 Sladen (talk | contribs) . . (2,003 bytes) +2,003 . . (initially populate based on news reports)
https://en.wikipedia.org/w/index.php?title=Alternate_Instruc...
Well that's disappointing.