ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - Intel Management Engine vulnerability SA-00086
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

Intel Management Engine vulnerability SA-00086

 Post Reply Post Reply Page  <1234 8>
Author
Message
soulstealer View Drop Down
Newbie
Newbie
Avatar

Joined: 30 Sep 2016
Location: Hon
Status: Offline
Points: 76
Post Options Post Options   Thanks (0) Thanks(0)   Quote soulstealer Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 3:39am
Originally posted by J Z J Z wrote:

Hello,

see -> http://forum.asrock.com/forum_posts.asp?TID=6676&title=wichtig-intel-mei-firmware-v118503425

sorry, but is this asrock official? we just need some clarity.
Back to Top
Kathrys View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote Kathrys Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 10:34am
Most motherboard manufacturers have already issued an update about incoming BIOS and software updates and we get silence?

I guess my next MB won't be an Asrock. Angry
Back to Top
parsec View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 May 2015
Location: USA
Status: Offline
Points: 4996
Post Options Post Options   Thanks (0) Thanks(0)   Quote parsec Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 12:56pm
Originally posted by daddyo daddyo wrote:

It was surprising to see how patronizing a moderator was regarding this issue. For those who have NOT read Intel's statement yet, they clearly have placed the initiative to resolve this serious security hole on the OEM providers, which Asrock would be in the case of motherboards.

Considering that any consumer Intel CPU made since fall of 2015 is affected, you can expect there will be attempts to make use of this vulnerability wherever it is unpatched. 

I await Asrock's official response.


-- Edit-- 

I did notice on their website that ME engine and CPU microcode updates have been released on some server motherboards, and 300 series chipset based motherboards... I hope more will come! I just bought my z270 extreme4 a month ago. I would expect them to issue updates for 200 and 100 series motherboards as well.


From the start of this, it was obvious that the only simple method of fixing this issue, is via a UEFI/BIOS update. The articles about this have very little detail, and are not definitive statements from Intel.

MY frustration is the mother board manufacture, ASRock in this case, being taken to task and at best blamed for the fix not being available immediately.

My main point only is, ASRock and all the other mother board manufactures are not responsible for this issue. Is that true or false?

We already see the angry posts in this thread, which is so frustrating. Yes, the mother board manufactures are stuck with the responsibility of providing the fix for this issue. But they did not create the IME hardware and software, any more than they manufacture the processors used in a mother board.

So why are people mad at ASRock?

They want a statement from ASRock, but what do they want it to say? That ASRock will provide the UEFI/BIOS updates? Of course, that is obvious and reasonable. How could any mother board manufacture not do that, provide the updates? I do not officially speak for ASRock in this case, but I'm sure as I can be that the UEFI/BIOS updates will be available.

I'm surprised anyone is concerned about the updates not being provided. Not providing the fix in a UEFI/BIOS update would alone be a huge PR disaster.

Back to Top
J Z View Drop Down
Groupie
Groupie
Avatar

Joined: 09 Sep 2016
Location: Germany
Status: Offline
Points: 976
Post Options Post Options   Thanks (1) Thanks(1)   Quote J Z Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 4:01pm
Originally posted by soulstealer soulstealer wrote:

Originally posted by J Z J Z wrote:

Hello,

see -> http://forum.asrock.com/forum_posts.asp?TID=6676&title=wichtig-intel-mei-firmware-v118503425

sorry, but is this asrock official? we just need some clarity.

Hello,

It is official and you can see the address from the link and it comes from ASRock only in advance and soon on the ASRock website Wink
Kind Regards,
JZ

https://shop.JZelectronic.de - Der Shop mit ausgesuchter ASRock Profi Hardware

https://www.facebook.com/asrock.de
Back to Top
romf View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 3
Post Options Post Options   Thanks (0) Thanks(0)   Quote romf Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 4:31pm
Forgive this dumb post, i just want to be notified of further announcements/posts here regarding this issue. Wink
Back to Top
Arukado_ View Drop Down
Newbie
Newbie


Joined: 22 Nov 2017
Status: Offline
Points: 12
Post Options Post Options   Thanks (0) Thanks(0)   Quote Arukado_ Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 4:48pm
Originally posted by parsec parsec wrote:


MY frustration is the mother board manufacture, ASRock in this case, being taken to task and at best blamed for the fix not being available immediately.


No my friend we not blame anyone for that. Your first post was like "go away and complain on Intels forum". Zero empathy means for some zero professional behavior.
If we had similar statement from Asrock as from other manufacturers for example "we are aware of this issue and we're working on fix ETA=XXX" nobody would be angry.

Originally posted by parsec parsec wrote:


My main point only is, ASRock and all the other mother board manufactures are not responsible for this issue. Is that true or false?


Yup that's true. The flaw is in ME but since Intel said go to your oem manufacturer cos you need bios update Asrock owners simply came here.

Originally posted by parsec parsec wrote:


So why are people mad at ASRock?


Cos there's no statement? Complete silence? And your first post? And answers from technical support like this one from raid-win forum which I pasted at the begging?

Originally posted by parsec parsec wrote:


They want a statement from ASRock, but what do they want it to say? That ASRock will provide the UEFI/BIOS updates?

That's exactly what we need / want.

Originally posted by parsec parsec wrote:


Of course, that is obvious and reasonable. How could any mother board manufacture not do that, provide the updates? I do not officially speak for ASRock in this case, but I'm sure as I can be that the UEFI/BIOS updates will be available.


Put yourself in other people shoes. They saw my post and your replay to it so .... what they suppose to think?


To summarize we all know that this kind of thing takes time. But why Asrock can't just inform their customers that company already working to provide patches etc.
For example my friend which have Asus Z170 plus got his patch yesterday. Furthermore JZ claims that in his post there's official Asrock solution so WTF? Is it or is it not?

Have a good day!

Back to Top
Arukado_ View Drop Down
Newbie
Newbie


Joined: 22 Nov 2017
Status: Offline
Points: 12
Post Options Post Options   Thanks (0) Thanks(0)   Quote Arukado_ Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 4:52pm
Originally posted by J Z J Z wrote:

Originally posted by soulstealer soulstealer wrote:

Originally posted by J Z J Z wrote:

Hello,

see -> http://forum.asrock.com/forum_posts.asp?TID=6676&title=wichtig-intel-mei-firmware-v118503425

sorry, but is this asrock official? we just need some clarity.

Hello,

It is official and you can see the address from the link and it comes from ASRock only in advance and soon on the ASRock website Wink


No no no JZ. Post is on Asrock forum but link with zip file which you provided http://asrock.pc.cdn.bitgravity.com/TSD/ME-consumer_11.8.50.3425.zip have Asrock in name but domain is totally different so from my point of view its not legit.

Back to Top
J Z View Drop Down
Groupie
Groupie
Avatar

Joined: 09 Sep 2016
Location: Germany
Status: Offline
Points: 976
Post Options Post Options   Thanks (1) Thanks(1)   Quote J Z Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 6:17pm
I'm sorry I wanted to help, then wait until it appears on the ASRock website. Other manufacturers have not provided anything official Wink
Kind Regards,
JZ

https://shop.JZelectronic.de - Der Shop mit ausgesuchter ASRock Profi Hardware

https://www.facebook.com/asrock.de
Back to Top
rico View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 30
Post Options Post Options   Thanks (0) Thanks(0)   Quote rico Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 7:10pm
Originally posted by J Z J Z wrote:

Other manufacturers have not provided anything official Wink


That's not entirely true though. My work laptop is a Lenovo ThinkPad T560 which the tool identified as already patched as are a whole lot of other models (but not all affected): https://support.lenovo.com/ie/en/product_security/len-17297

Quote
INTEL-SA-00086 Detection Tool

Risk Assessment

Based on the analysis performed by this tool: This system is not vulnerable. It has already been patched.

For more information refer to the SA-00086 Detection Tool Guide or the Intel security advisory Intel-SA-00086 at the following link: https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr

INTEL-SA-00086 Detection Tool

Application Version: 1.0.0.128
Scan date: 23/11/2017 11:00:35

Host Computer Information

Name: XXXXXXXXX
Manufacturer: LENOVO
Model: 20FJS06J00
Processor Name: Intel(R) Core(TM) i7-6600U CPU @ 2.60GHz
OS Version: Microsoft Windows 10 Enterprise

Intel(R) ME Information

Engine: Intel(R) Management Engine
Version: 11.8.50.3425
SVN: 3

Copyright(C) 2017, Intel Corporation, All rights reserved.


Not complaining but would reiterate OP's request for a comment on the matter. I'm not expecting a patch by the end of the day!

Fatal1ty Z170 Gaming K6+ owner.




Edited by rico - 23 Nov 2017 at 7:11pm
Back to Top
Arukado_ View Drop Down
Newbie
Newbie


Joined: 22 Nov 2017
Status: Offline
Points: 12
Post Options Post Options   Thanks (0) Thanks(0)   Quote Arukado_ Quote  Post ReplyReply Direct Link To This Post Posted: 23 Nov 2017 at 7:14pm
Originally posted by J Z J Z wrote:

I'm sorry I wanted to help, then wait until it appears on the ASRock website. Other manufacturers have not provided anything official Wink


That's no true at all. For example my friend patch his mobo yesterday.
https://www.asus.com/pl/Motherboards/Z170M-PLUS/HelpDesk_BIOS/

Patch from yesterday MEUpdateTool

Back to Top
 Post Reply Post Reply Page  <1234 8>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.094 seconds.