Intel (Converged Security) Management Engine: Drivers, Firmware and Tools (2-15)

Intel ME 11.0 Consumer PCH-H Firmware v11.0.0.1205

Capture.PNG



Note 1: VCN was increased to 12, no downgrade possible after updating.

Note 2: Add this line to DB to add support:

11.0.0.1205_CON_H_XX_PRD_RGN_BA6F0B1FBD8F2AD4575B6C1EAA3118CB5CEB9919_SHA1

Can i ask how can i be sure it flashed ok without any problems?

Also what can i expect if the fw is not stable? BSOD? freezes?

Thanks

Is it possible upgrade this?

I canĀ“t do it!! I flash latest Me firwmare (IntelĀ® Management(ME) 11.0.0.1205 (Firmware) (08-02-2016), flashed good, but after I execute Intel Me shown 11.0.0.68.

Any ideas please?



Thanks for your work!!

Greats from Spain

@ karserasl:

MEInfo and MEManuf. Read the first post carefully, everything you need is there.

@el_zari

You didnā€™t mention the motherboard. I have seen this on an ASUS Sabertooth Z170 Mark 1 motherboard in the past. Basically, I assume that itā€™s happening on all ASUS BIOS that come with the DE90FFA8 GUID, which is what ME Analyzer has detected as well. The person that had this issue claimed that for some reason he was able to update at some point without the firmware reverting back but didnā€™t know exactly why that time it worked. What motherboard do you have? Are you using the latest FWUpdate version to update?

Yes, I use UBU 1.47.1 for update.

I have Asus Z170 DELUXE 1602 bios. I attatch it here!!



Thanks a lot.

Z170D EL_ZARI.rar (7.23 MB)

Intel ME 11.0 Corporate PCH-H Firmware v11.0.0.1205

Capture.PNG



Note: VCN was increased to 12, no downgrade possible after updating.

MEA DB: 11.0.0.1205_COR_H_XX_PRD_RGN_233838C4DDDE3F38617B4FFD1E35F5B03A7F5371_SHA1

Also, I have added a warning for 100-series and revised the already existing one for 8-series:

Capture2.PNG



@ el_zari:

You cannot use UBU for ME firmware updating. Only FWUpdate as provided and instructed at the first post. I suspect you donā€™t understand what MEA shows exactly. Use FWUpdate with 11.0.0.1205 CON H and, after restarting, run MEInfo. What FW Version do you see?

Thanks for responseā€¦

I used FwUpdate with 11.0.0.1205_CON_H.bin firmware in my Z170 DEluxe. All ok, 100% Flash.

After, I reboot my pc and run MeINfo64:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
Ā 

Intel(R) MEInfo Version: 11.0.0.1202
Copyright(C) 2005 - 2015, Intel Corporation. All rights reserved.
Ā 

Ā 
Intel(R) ME code versions:

BIOS Version 1602
MEBx Version 0.0.0.0000
GbE Version 0.7
Vendor ID 8086
PCH Version 31
FW Version 11.0.0.1205 H
LMS Version Not Available
MEI Driver Version 11.0.0.1172
Wireless Hardware Version Not Available
Wireless Driver Version Not Available

FW Capabilities 0x31111D40

Intel(R) Capability Licensing Service - PRESENT/ENABLED
Protect Audio Video Path - PRESENT/ENABLED
Intel(R) Dynamic Application Loader - PRESENT/ENABLED
Intel(R) Platform Trust Technology - PRESENT/DISABLED

TLS Disabled
Last ME reset reason Firmware reset
Local FWUpdate Enabled
BIOS Config Lock Disabled
GbE Config Lock Disabled
Host Read Access to ME Disabled
Host Write Access to ME Disabled
Host Read Access to EC Disabled
Host Write Access to EC Disabled
SPI Flash ID 1 EF4018
SPI Flash ID 2 Unknown
BIOS boot State Post Boot
OEM ID 00000000-0000-0000-0000-000000000000
Capability Licensing Service Enabled
OEM Tag 0x00000000
Slot 1 Board Manufacturer 0x00000000
Slot 2 System Assembler 0x00000000
Slot 3 Reserved 0x00000000
M3 Autotest Disabled
C-link Status Disabled
Independent Firmware Recovery Disabled
EPID Group ID 0xF8D
OEM Public Key Hash FPF 0000000000000000000000000000000000000000000000000000000000000000
OEM Public Key Hash ME 0000000000000000000000000000000000000000000000000000000000000000
ACM SVN FPF 0x0
KM SVN FPF 0x0
BSMM SVN FPF 0x0
GuC Encryption Key FPF 0000000000000000000000000000000000000000000000000000000000000000
GuC Encryption Key ME 0000000000000000000000000000000000000000000000000000000000000000

FPF ME
--- --
Force Boot Guard ACM Disabled Disabled
Protect BIOS Environment Disabled Disabled
CPU Debugging Enabled Enabled
BSP Initialization Enabled Enabled
Measured Boot Disabled Disabled
Verified Boot Disabled Disabled
Key Manifest ID 0x0 0x0
Enforcement Policy 0x0 0x0
PTT Disabled Enabled
PTT Lockout Override Counter 0x0
EK Revoke State Not Revoked
PTT RTC Clear Detection FPF 0x0

Ā 
Ā 


Do you see something wrong?

Thanks

So your firmware is updated. MEA shows the firmware version of the SPI Image you downloaded from the OEM and not the one that you flashed on your SPI Chip. Fernando has written one or two lines at the UBU Thread > ME Analyzer subsection to explain that in case someone is confused on what MEA shows exactly.

Ok, perfect my friend.

IĀ“m going to read Me Analyzer subsection.

Thanks for your help.

Regards from Spain.

@plutomaniac One question more pleaseā€¦

I backup it my bios. (view attached)



If open with UBU, show me UNIDENTIFIABLE INTEL ENGINE FIRMWAREā€¦REPORT THIS ISSUE

ItĀ“s normal or itĀ“s a bug?

Thanks again!!

bios.rar (5.89 MB)

Honestly, everyone, this is simply too much of a struggle. Intel and Microsoft should get together as much as they need to in order to prevent this sort of thing from inflicting itself on users.

It is one thing for enthusiasts like many of you here on this forum to tweek hardware and software ā€“ the equivalent of those who work on ā€œstreet carsā€ in the automotive world.

It is quite another to put regular folks like me through this kind of pain in order for them simply to do things like hibernate, sleep or just gracefully shut down their computers, particularly laptops.

I for one am very ready to jump into any hardware and OS that wonā€™t inflict themselves on me.

If anyone from Intel and MS are reading this ā€“ take note!

@ el_zari:

The ME Region is not included in that SPI image. If your flash descriptor is locked then you cannot create a full SPI dump and the ME Region is skipped. Since the ME Region is empty but the reference to itā€™s presence is still there at the SPI dumpā€™s Flash Descriptor, MEA categorizes it as ā€œunidentifiableā€, in this case: empty.

Ok, perfect

Any method for flash full dump bios with ME REGION? is it possible unlock flash descriptor?

Thanks again!!

@ el_zari:

To dump the full SPI image you need either an unlocked flash descriptor or a programmer. Unlocking the descriptor is possible but not always easy. Until I write a guide on the Flash Descriptor, check the previous pages on how to unlock it using the ā€œpinmodā€. Iā€™ve mentioned it multiple times in the past.

Hello,
I have a Maximus vii impact , and wanting to get off the bios, I find myself with this.
what can I do?
thank you
I am French using Google translation


@ Nexus35:

If you continue what you are doing because youā€™ll probably end up with a bricked system, if thatā€™s not the case already. What are you trying to do exactly? Dump the contents of the SPI chip or flash something? What Region do you want to dump/flash, or is it the whole SPI chip? More info is required.

I have question: how repleace intel me region in bios dump with intel me version 7.x. With intel me version 8.x and above this is no problem, but when try to do this with bios dump with intel me 7.x, i download intel me image from this topic and i canā€™t repleace it because image from this topic have diffrent structure then intel me from bios dump.
Sorry for my English.

I donā€™t understand what you are trying to do and why. Please explain in more detail. If your system has ME8, you stay at ME8. You cannot downgrade to ME7 and you have no reason to. Also, the firmware provided at the first post are meant for FWUpdate. To add into an SPI image you need to use FITC with a Region (not Update) image and adjust settings according to the ones your OEMā€™s latest ME has.

I try to explain: i have a bios dump with ME7 what is broken, i try to repleace it with ME image from first page of this topic, but ME7 image from first page have other structure than ME7 from bios dump. When i have this same problem with ME8 or above i can replace ME in bios dump with ME image from this topic.

Intel ME 11.0 Consumer PCH-LP Firmware v11.0.0.1202 is out!
http://www.station-drivers.com/index.phpā€¦id=2058&lang=fr