[REQUEST] HP ZBook Fury G9 Undervolt unlocking

Hi all,

I was trying to unlock the undervolting for the BIOS of HP ZBook Fury G9. The BIOS file is available for downloading here and after extracting the BIOS image can be found (interestingly larger than 32M). I was looking for the usual suspects for overclock lock cfglock etc. and I could not find anything there. UEFITool extracted sections can not be converted to text via ifrextract.exe. So no clues how to enable the undervolt unlocking information.

Sounds silly, but I have access to an ME 16.0 BIOS laptop and CpuSetup hex dump looked similar and I set the offset 0x43 on the HP similar to the other laptop and on reboot it went back to 1.

Can you help me with unlocking the undervolting?

Thanks,
DM

Link to the extracted BIOS image.

https://file.io/h9BJ35MvCk5l

Its an InsydeH2O bios, look for their tools and methods in the forum, maybe H2OUVE can help you.

Hi,

do you by any chance have the bin file from your Fury G9 ?

Unfortunately I don’t have it anymore but you can download it directly from HP and extract the image from the executable just by running it.

https://ftp.hp.com/pub/softpaq/sp144501-145000/sp144595.exe

Uhhhh this one is fun, it seem sections of it are signed. There is also mention to Intel Boot Guard, but I think that could be disabled in the setup prior to flashing a modified version, but if what needs to be changed lies in the RSA protected area there’s little to be done.

I wonder if via SREP one would be able to tweak things at runtime and not trigger the signature checks, might look at this one I can allocate some time, I’m curious.

What’d be of it all when the chain of trust starts in the silicon itself…