Intel (Converged Security) Management Engine: Drivers, Firmware and Tools (2-15)

Updated the notice regarding INTEL-SA-00075/CVE-2017-5689 (found 11.0.18.3003 from HP):



Intel ME System Tools v11.0 r4 (ReUp)
Intel ME System Tools v9.1 r2 (ReUp)



Intel ME System Tools v9.1


You cannot downgrade from 9.1 to 9.0 without the use of programmers or SPI flashers


The BIOS must be updated from the OEM, nothing you can do

If you are ok with ending up with a problematic ME implementation and want to risk it then you certainly can. Make sure you have the latest BIOS applied first just in case the OEM has added 9.1 support but did not bother to update the ME firmware alongside that change (it happens).


The BIOS must be updated from the OEM, nothing you can do

If you are ok with ending up with a problematic ME implementation and want to risk it then you certainly can. Make sure you have the latest BIOS applied first just in case the OEM has added 9.1 support but did not bother to update the ME firmware alongside that change (it happens).





@plutomaniac

Thanks. I flashed to 9.1 some years ago. Then I read that the chipset HM86 was not supposed to run 9.1 - hardware limitation. I had to ground a pin to bypass protection and flash it back to 9.0.

If the changes are just new settings or modules, I can do something with the hidden variables and modules. Would you know of the changes needed?

Thanks a lot for the answer, even if itā€™s not what I wanted to hear :slight_smile:
Youā€™re right, I donā€™t think Intel has any reason to fix the 9.0 tree. I wonder, if the OEMs will offer something? Up to now there are only few Q87- boards that earlier got an update to AMT 9.1. Dfi did all I could find, Asrock one board, but Gigabyte, Msi and Asus did none- even if Asus for example still updated the bios for the Q87M-E in 2016. I wonder if Asus will offer something for their Q87- boards, there is a time schedule that says EOL will be as late as 2020! (Itā€™s called " 5 year longevity motherboard program" .

Is there a way to find out? Or could you give a hint, where to find further information? I tried to find some release notes for AMT 9.1 or pages that refer to the differences between 9.0 and 9.1 (and bios requirements) without any success.



You make too many assumptions, because I never even touched or flashed the ME to cause the problem, this is a problems with these motherboards by default, I came here trying to find some help since Asus are a POS and dont support or provide support for their product.

I have kept plutomaniac up-to-date with my Attempts to fix it and am still trying to get answers to some questions. (he answered main question) Ad nauseam but I still have ME related questions.
As to your suggestion- "They" cant be taking 24/7 systems off-line for that long until an alternative is possible that allows your kind of suggestion which plutomaniac already provided answer for.

@plutomaniac
Could I flash the 1.7.0.1229 ME on this board?
also if the VCN is what prevents ME downgrades is it safe to assume that as long as VCN is the same then a downgrade is possible?
Could I flash the corporate ME on this?

@atomota ,

I really did not mean any offense and if I misunderstood your statements please have my appologies.
Also dont take my curiosity too seriously as whatever interpretation on your actions or not was not meant
to be personal.

Thank you.


Technically yes as 11.7 is an upgrade path for 11.0,11.5 and 11.6 but we always suggest to wait for an updated BIOS from the OEM first (which wonā€™t happen for 11.7 yet because KBL-R is not released)


Upgrading/Downgrading is controlled by Security Version Number (SVN), Version Control Number (VCN) and PV-bit. SVN is always 1 so far and VCN, PV can both be seen at MEA. For PV, you cannot upgrade to No from Yes if I remember properly.


Iā€™m not even going to answer thatā€¦

Mine b85 asus has no overclocking capabilities so if i have problems i will have only with fans?

Also i find this: Intel ME FW 9.1.0.1015
Pacman managed to flash 9.1.0.1015 to his Maximus VI Gene, using an external programmer.


the packet tool back then in 2013 failed with a SKU mismatch so he used an external programmer.

Now the packet tools that have updated means that it will not the update stack with this reason?
Because finally it seems that asus bios is ok to take 9.1.

Only Intel ā€œvProā€ chipset boards are affected by this newly discovered Intel ME vulnerability.
Thereā€™s a video and downloadable ā€œDisable Intel AMTā€ software here:
http://www.majorgeeks.com/files/details/ā€¦_intel_amt.html
Consumer chipset boards such as Z87, Z97, Z170, & Z270 boards are unaffected; Hxxx series boards are also considered as consumer chipsets.
Business boards such as Bxxx series (or even less common Qxxx series) chipset boards may be vulnerable, but ONLY when also running the Intel AMT software.
Thatā€™s my current understanding of the desktop chipset situation, anyway.
Not too sure about specifics on laptop chipsets.

How To Find IntelĀ® vProā„¢ Technology Based PCs
https://communities.intel.com/docs/DOC-5693

Business boards always use the 5 Mb ME firmware, while Consumer boards always use the 1.5 Mb ME firmware.
At least for newer chipset (since ~2010 or later) boards.

ME 8.1.71.3608 from HP

Intel ME 8 5MB Firmware v8.1.71.3608 (INTEL-SA-00075/CVE-2017-5689)

Capture.PNG



Note: This is the first ME8 firmware after 8.0.0.1340 which has a raised Version Control Number (VCN) of 3 instead of 2. At ME8 generation Intel wasnā€™t really using the VCN but this new firmware does. You cannot downgrade to lower ME8 firmware via FWUpdate after applying 8.1.71.3608.

Updated the notice regarding INTEL-SA-00075/CVE-2017-5689 (found 8.1.71.3608 from HP):

bug.PNG

I updated my Asus b85 plus latest bios with the latest 9.1 ime firmware. (Intel ME 9.0 5MB Firmware v9.0.31.1487 ā€”>Intel ME 9.1 5MB Firmware v9.1.41.3024).
I used the 11.7.0.1002 driver.
MEInfo ā†’ passed
MEManufā€“> passed



cooler fan control from bios passed
fsb before update 99.76 and after update 99.76 passed
all good in device manager passed

What methods did you use to test them all?

For the first two the tools.
For the others my personal experience before and after update.
Also sleep, hybarnate and rapid start work as intented.
ram speed multyplier works.
xmp works.
eist-turbo boost works.
core voltage change as intented and last fan control from bios works as temperanture control.

The only think i cant test is the fsb overclocking because b85 has no overclocking abilities by fsb.

So all the other fuction works.
If someone know what other test i can make to test if the implamation was good, feel free to tell me.

My laptop has Z97 chipset with Core i7 4790K Desktop Processor. The ME Firmware version is 9.1.20.1035. I had certain concerns about updating the ME Firmware:

1. If I upgrade the ME Firmware of the system to 9.1.37.1002 by using FWUpdLcl64 -F 9.1.37.1002_1.5MB_PRD_RGN.bin command (from Intel ME System Tools v9.1 R2), could there be any risks? After the update, I suppose I need to Power Off the system and remove the battery for 30 seconds or something?

2. Can the Fan Control of the laptop or the software utility which allows setting different Fan curves have dependency on a specific Firmware version to work properly? Can updating the Firmware disturb their function?

3. Will it be possible to go back to the previous Firmware, if the new Firmware causes any problem?

4. If a BIOS update comes later which has an older ME version, can updating BIOS cause a problem? Will I have to modify the BIOS update file with the new ME data before updating?

My last question is that now that i have updated Ime, if ever asus updated the bios the ime will be rewritten with an old version, or my bios will updated without change the ime version?

https://downloadcenter.intel.com/download/26755
Head over and check out Intelā€™s Detection Guide as well as an identification tool.

Intel has stated that it is not a problem with consumer based PCs.

Intel ME 7 5MB Firmware v7.1.91.3272 (INTEL-SA-00075/CVE-2017-5689)

Capture.PNG



Updated the notice regarding INTEL-SA-00075/CVE-2017-5689 (found 7.1.91.3272 from HP):

bug.PNG



@ akm:

1. Noone can rule out the risks but itā€™s pretty safe. Flashing under DOS or EFI is even better to avoid any 3rd party OS interferences. FWUpdate will ask you to restart when it is done, nothing else is needed.
2. No.
3. No (check Version Control Number - VCN at the first post).
4. That highly depends on your OEMā€™s method for BIOS updating. I know Dell is a little quirky but I donā€™t usually hear of any such issues.

@ boombastik:

Almost always no because the Flash Descriptor is locked at ASUS systems and their BIOS Flashback targets the BIOS region only of the SPI chip regardless.

@akbaarā€¦Well, it is a shame that Intel will not think about consumerā€™s pc with 1,5mb firmware even if itā€™s statedā€¦It will takes months before finding one anyway (if they decide to)


Just to confirm the process for flashing under DOS, it would be:

1. I create an MS-DOS formatted USB (using Rufus tool)
2. Put the FWUpdLcl.exe (from Local-DOS folder of Intel ME System Tools v9.1 R2) and 9.1.37.1002_1.5MB_PRD_RGN.bin to the root of the DOS formatted USB
3. Boot from the USB and execute FWUpdLcl.exe -F 9.1.37.1002_1.5MB_PRD_RGN.bin
4. Restart the system (No need to Power Off and remove the battery)

Please confirm if any changes needed in the above process.


My system has AMI Bios. The BIOS update process requires creating an MS-DOS disk and using Fpt, AFUDOS, OAIDDOS commands etc. I believe if I get a BIOS update after updating the ME Firmware, I can just go ahead with the update without worrying about ME firmware version in the BIOS update file. Right?


According to your info, I infer that you are using a CLEVO laptop.


Yes, but you should not run MESET while updating, or the ME region will get overwritten.