ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - Intel Management Engine vulnerability SA-00086
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

Intel Management Engine vulnerability SA-00086

 Post Reply Post Reply Page  123 8>
Author
Message Reverse Sort Order
arturk View Drop Down
Newbie
Newbie


Joined: 07 Jul 2017
Status: Offline
Points: 13
Post Options Post Options   Thanks (0) Thanks(0)   Quote arturk Quote  Post ReplyReply Direct Link To This Post Topic: Intel Management Engine vulnerability SA-00086
    Posted: 22 Dec 2017 at 7:15am
I received confirmation from support that HDCP should work after IME patch. This convinced me that propably there is something wrong with my setup. I decided to clear CMOS data and after that everything started to work... partially :-)

Why partially? Well I discovered that when I have 1080ti plugged into slot and integrated graphic card is active (set as primary device) HDCP feature with Intel is not working anymore. I'm 100% sure that before applying IME patch HDCP was working OK, no matter which card I was using. Notice that only Intel's intergrated graphic card can provide required PAVP for playing BR UHD movies. Do the math and guess why I'm missing it :-)

PS.
Asrock EU support - thanks for help!
Back to Top
dlee View Drop Down
Newbie
Newbie


Joined: 22 Dec 2017
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote dlee Quote  Post ReplyReply Direct Link To This Post Posted: 22 Dec 2017 at 4:49am
I updated my Z270M Pro4 with the MEI firmware.  After updating, the Intel vulnerability check tool says the board is no longer vulnerable, but also reports that the some sort of licensing services needs to be updated too.  I don't use the board's HDMI output, but that is probably why HDCP isn't working after the MEI update.  Some licensing firmware is now broken.


Edited by dlee - 22 Dec 2017 at 4:50am
Back to Top
flashback8 View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote flashback8 Quote  Post ReplyReply Direct Link To This Post Posted: 22 Dec 2017 at 4:47am
Originally posted by arturk arturk wrote:

I've made contact with Asrock support. Hope they will realize that with Z270 itx there is same problem as with Z370 before BIOS update... 


The interesting thing is that I've been in touch with a guy who has a Z170 board. He doesn't have HDR on his setup but he has updated ME and the LSPCON chip firmware willy-nilly in the hopes of enabling HDR. Apparently, HDCP 2.2 has worked fine the entire time. Makes me think that ASRock added something starting with Z270 that can only be kept in place with a BIOS update. If so, that's really unfortunate if more problems come up down the road after Z370 support is dropped.
Back to Top
arturk View Drop Down
Newbie
Newbie


Joined: 07 Jul 2017
Status: Offline
Points: 13
Post Options Post Options   Thanks (0) Thanks(0)   Quote arturk Quote  Post ReplyReply Direct Link To This Post Posted: 21 Dec 2017 at 7:05pm
I've made contact with Asrock support. Hope they will realize that with Z270 itx there is same problem as with Z370 before BIOS update... 
Back to Top
flashback8 View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote flashback8 Quote  Post ReplyReply Direct Link To This Post Posted: 21 Dec 2017 at 3:50pm
Originally posted by arturk arturk wrote:

Unfortunately I can confirm that on Z270 Gaming-ITX/ac after ME update HDCP 2.2 is not working anymore. Before update everything was OK... For me this is very problematic since Netflix in 4K and BR UHD support is very important part of my setup.

I've tried newest Intel Graphic drivers (15.60.01.4877), different versions of ME software - no luck...

Does anybody found fix for HDCP support?  Motherboards with Z370 receiverd Bios update fixing this issue, but for Z270 there is nothing...


Oh no! I'd recommend calling ASRock tech support. Don't rely on this forum. Call ASRock directly. While the tech support guy never actually got back to me as he promised (not necessary since the BIOS update fixed everything), he did say he knew what to do to fix it, and would send me a link to the appropriate software.

Also, just FYI, the update I applied for my Z370 board was a specific BIOS posted under the board's support page. It looks like there isn't one for the Z270 yet. Definitely point this out to ASRock when you call.


Edited by flashback8 - 21 Dec 2017 at 3:57pm
Back to Top
arturk View Drop Down
Newbie
Newbie


Joined: 07 Jul 2017
Status: Offline
Points: 13
Post Options Post Options   Thanks (0) Thanks(0)   Quote arturk Quote  Post ReplyReply Direct Link To This Post Posted: 19 Dec 2017 at 6:30pm
Unfortunately I can confirm that on Z270 Gaming-ITX/ac after ME update HDCP 2.2 is not working anymore. Before update everything was OK... For me this is very problematic since Netflix in 4K and BR UHD support is very important part of my setup.

I've tried newest Intel Graphic drivers (15.60.01.4877), different versions of ME software - no luck...

Does anybody found fix for HDCP support?  Motherboards with Z370 receiverd Bios update fixing this issue, but for Z270 there is nothing...

Back to Top
flashback8 View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote flashback8 Quote  Post ReplyReply Direct Link To This Post Posted: 06 Dec 2017 at 5:28am
Originally posted by rico rico wrote:

Originally posted by flashback8 flashback8 wrote:

Hello. As a fair warning to all out there, if your board is a Gaming-ITX/ac board (Z170, Z270, or Z370), you should consider not flashing the ME firmware that was mentioned by ASRock tech support. Long story short, if you care about anything that uses HDCP 2.2 (just Ultra HD Blu-Rays and possibly 4K Netflix for now), there's something generic about the firmware that breaks HDCP 2.2. ASRock just posted v1.40 of my board's BIOS (Z370), which updates the ME firmware and possibly reflashes the LSPCON (MegaChips MDCP2800) firmware. Finally, HDCP 2.2 functionality was restored on my system.


Maybe your issue only applies to 300 series but not 100 & 200? ASRock have changed the wording of the ME patch download page to be no longer applicable to 300 series motherboards: https://www.asrock.com/microsite/2017IntelFirmware/


Interesting. That definitely wasn't present yesterday. (I happened to look.) I suppose the only way to find out would be if somebody with a functioning 4K setup and a Z170 or Z270 Gaming-ITX/ac board took one for the team and upgraded. I think I might know somebody who can check. Come to think of it, I think he was upgrading his ME firmware willy nilly (11.6 -> 11.7) and HDCP 2.2 never broke. Strange, but who knows, maybe the Z370s do have something specific in the background.
Back to Top
rico View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 30
Post Options Post Options   Thanks (0) Thanks(0)   Quote rico Quote  Post ReplyReply Direct Link To This Post Posted: 06 Dec 2017 at 5:05am
Originally posted by flashback8 flashback8 wrote:

Hello. As a fair warning to all out there, if your board is a Gaming-ITX/ac board (Z170, Z270, or Z370), you should consider not flashing the ME firmware that was mentioned by ASRock tech support. Long story short, if you care about anything that uses HDCP 2.2 (just Ultra HD Blu-Rays and possibly 4K Netflix for now), there's something generic about the firmware that breaks HDCP 2.2. ASRock just posted v1.40 of my board's BIOS (Z370), which updates the ME firmware and possibly reflashes the LSPCON (MegaChips MDCP2800) firmware. Finally, HDCP 2.2 functionality was restored on my system.


Maybe your issue only applies to 300 series but not 100 & 200? ASRock have changed the wording of the ME patch download page to be no longer applicable to 300 series motherboards: https://www.asrock.com/microsite/2017IntelFirmware/

Before:
Quote
Affected ASRock Products:
Intel 100, 200, 300
ME1 ME2

If your model Intel 100/200/300 series but not in the following list, please download ME1 package


Now:
Quote
Intel 300 series
ASRock provides the BIOS for customers to update the ME firmware.
Please refer to the download link for ASRock 300 series motherboards:
http://www.asrock.com/support/index.asp?Model=Z370

Intel 100 and 200 series
ASRock provides the firmware package for customers to update the ME firmware.
There are 2 kinds of ME packages.
If your model is Intel 100/200 series but not in the following list, please download package ME1.
ME1


Back to Top
flashback8 View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote flashback8 Quote  Post ReplyReply Direct Link To This Post Posted: 06 Dec 2017 at 1:58am
Hello. As a fair warning to all out there, if your board is a Gaming-ITX/ac board (Z170, Z270, or Z370), you should consider not flashing the ME firmware that was mentioned by ASRock tech support. Long story short, if you care about anything that uses HDCP 2.2 (just Ultra HD Blu-Rays and possibly 4K Netflix for now), there's something generic about the firmware that breaks HDCP 2.2. ASRock just posted v1.40 of my board's BIOS (Z370), which updates the ME firmware and possibly reflashes the LSPCON (MegaChips MDCP2800) firmware. Finally, HDCP 2.2 functionality was restored on my system. This post points to some potential info if you're curious about what might be happening deep in the motherboard.

Good luck!

Originally posted by rico rico wrote:

Looks like today's your lucky day, flashback8.


Indeed it is! :) That said, please note that SGX was never the problem (AFAIK). It was something far deeper. The Cyberlink advisor never complained about SGX. I'm assuming that ASRock made some sort of change in the BIOS that made SGX detection and such a bit smarter. It could be that the "Auto" SGX enabling now works instead of having to keep it turned on all the time ("Enabled"). I'll play with it and see what comes up.


Edited by flashback8 - 06 Dec 2017 at 2:01am
Back to Top
rico View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 30
Post Options Post Options   Thanks (0) Thanks(0)   Quote rico Quote  Post ReplyReply Direct Link To This Post Posted: 05 Dec 2017 at 7:10pm
Originally posted by flashback8 flashback8 wrote:


Thanks for the suggestion. Didn't help.


Looks like today's your lucky day, flashback8.

https://www.asrock.com/MB/Intel/Fatal1ty%20Z370%20Gaming-ITXac/index.asp#BIOS

1.Update Intel ME 11.8.50.3425.
2.Update Microcode
3.Enhance CPU performance.
4.Enable Intel SGX

Back to Top
 Post Reply Post Reply Page  123 8>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.094 seconds.