ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - Intel Management Engine Issue INTEL-SA-00086 Fix
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

Intel Management Engine Issue INTEL-SA-00086 Fix

 Post Reply Post Reply Page  <1 23456 13>
Author
Message
rico View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 30
Post Options Post Options   Thanks (0) Thanks(0)   Quote rico Quote  Post ReplyReply Direct Link To This Post Posted: 07 Dec 2017 at 6:58am
Intel(R) ME Firmware ICC Tools User Guide.pdf:

Quote
Intel® Management Engine Firmware Integrated Clock Controller (ICC) Tool
 
Tools User Guide
January 2017
Revision 0.5
 
Intel Confidential


lol. whoops. In fact, I'm not even sure that whole /Tools folder should even be in there :)

In any case, this download isn't just for Kaby Lake. It's also applicable to my Skylake system on Z170 Gaming K6+ but I've already been running these ME drivers for the last week: http://forum.asrock.com/forum_posts.asp%3FTID=6667&PID=40181&title=intel-management-engine-vulnerability-sa00086#40181

To install new device drivers (not firmware!) just run any of the setup apps in the Installers folder. They're all the same and you end up with driver v11.7.0.1045 running Intel Management Engine Interface under System devices (Device Manager).


Back to Top
Kladno View Drop Down
Newbie
Newbie


Joined: 15 Aug 2016
Status: Offline
Points: 34
Post Options Post Options   Thanks (1) Thanks(1)   Quote Kladno Quote  Post ReplyReply Direct Link To This Post Posted: 08 Dec 2017 at 5:17am
Yes, I know how to install it and today there is a 'new' version without any 'classified' files, only 3.56 MB.

Back to Top
Truman View Drop Down
Newbie
Newbie


Joined: 05 Dec 2017
Status: Offline
Points: 4
Post Options Post Options   Thanks (0) Thanks(0)   Quote Truman Quote  Post ReplyReply Direct Link To This Post Posted: 09 Dec 2017 at 11:10am
I am using an Intel Core i7-7800X
Back to Top
Natanji View Drop Down
Newbie
Newbie
Avatar

Joined: 20 Dec 2016
Status: Offline
Points: 8
Post Options Post Options   Thanks (0) Thanks(0)   Quote Natanji Quote  Post ReplyReply Direct Link To This Post Posted: 10 Dec 2017 at 9:17am
Hi, I just discovered (by using Intel's testing tool) that my Asrock J3455M is also affected. But I can't see which of these is the correct version (ME1 or ME2) for me to download when I have an Apollolake board? Or are you still working on a patch for that one?

Quote INTEL-SA-00086 Detection Tool
Copyright(C) 2017, Intel Corporation, All rights reserved

Application Version: 1.0.0.146
Scan date: 2017-12-10 01:07:20 GMT

*** Host Computer Information ***
Name: <confidential>
Manufacturer: To Be Filled By O.E.M.
Model: To Be Filled By O.E.M.
Processor Name: Intel(R) Celeron(R) CPU J3455 @ 1.50GHz
OS Version:    (4.14.3-1-ARCH)

*** Intel(R) ME Information ***
Engine: Intel(R) Trusted Execution Engine
Version: 3.0.2.1108
SVN: 1

*** Risk Assessment ***
Based on the analysis performed by this tool: This system is vulnerable.
Explanation:
The detected version of the Intel(R) Trusted Execution Engine firmware
  is considered vulnerable for INTEL-SA-00086.
  Contact your system manufacturer for support and remediation of this system.


PS: Is it really not possible to log on to this board here with HTTPS? Feels kinda bad to send my password in the open...


Edited by Natanji - 10 Dec 2017 at 9:22am
Back to Top
GTwannabe View Drop Down
Newbie
Newbie


Joined: 12 Dec 2017
Status: Offline
Points: 5
Post Options Post Options   Thanks (0) Thanks(0)   Quote GTwannabe Quote  Post ReplyReply Direct Link To This Post Posted: 12 Dec 2017 at 3:17am
Tag for info on IME patch.
Back to Top
Krautmaster View Drop Down
Newbie
Newbie


Joined: 28 Nov 2017
Status: Offline
Points: 22
Post Options Post Options   Thanks (0) Thanks(0)   Quote Krautmaster Quote  Post ReplyReply Direct Link To This Post Posted: 14 Dec 2017 at 10:46pm
waiting for somthing flashable for my x299 i9 prof gaming + i9 7980 XE.


The provided one wants to do a downgrade from 

C:\Users\kraut\Downloads\ME-consumer_11.8.50.3425\ME-consumer_11.8.50.3425\Windows64>FWUpdLcl64.exe -fwver

Intel (R) Firmware Update Utility Version: 11.8.50.3425
Copyright (C) 2007 - 2017, Intel Corporation.  All rights reserved.

FW Version: 11.10.0.1287

------------

the Intel check tool stucks with all drivers and win fresh setup

C:\Users\kraut\Downloads\SA00086_Windows\SA00086_Windows\DiscoveryTool>Intel-SA-00086-console.exe

Unbehandelte Ausnahme: System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
   bei System.Security.Principal.NTAccount.Translate(IdentityReferenceCollection sourceAccounts, Type targetType, Boolean forceSuccess)
   bei System.Security.Principal.NTAccount.Translate(Type targetType)
   bei System.Security.AccessControl.CommonObjectSecurity.ModifyAccess(AccessControlModification modification, AccessRule rule, Boolean& modified)
   bei System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(AccessRule rule)
   bei DiscoveryTool.FileExtractor.Extract(String directoryName, Boolean localization)
   bei DiscoveryTool.CLI.Program.Main(String[] args)


Edited by Krautmaster - 14 Dec 2017 at 10:47pm
Back to Top
BWolf View Drop Down
Newbie
Newbie


Joined: 17 Dec 2017
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote BWolf Quote  Post ReplyReply Direct Link To This Post Posted: 17 Dec 2017 at 1:07pm
Did anyone find a fix for Error 8719: Firmware update cannot be initiated because Local Firmware update is disabled yet?

I have a Z170 Gaming K4.
Waiting now for 1 month and no new patches seem to come out that fix this, very unsettling.
Back to Top
BWolf View Drop Down
Newbie
Newbie


Joined: 17 Dec 2017
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote BWolf Quote  Post ReplyReply Direct Link To This Post Posted: 17 Dec 2017 at 2:25pm
I resorted to flashing my BIOS, after that the error was gone and the fix worked.
I would have rather not done it, next time I will invest into a double bios board.
Back to Top
rico View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 30
Post Options Post Options   Thanks (0) Thanks(0)   Quote rico Quote  Post ReplyReply Direct Link To This Post Posted: 17 Dec 2017 at 11:28pm
The Z170 Gaming K4 IS a double BIOS board :/

Anyways, the INTEL patch didn't work first time for me either but re-flashing my BIOS worked for me too. Again, this isn't even an ASRock patch.
Back to Top
arturk View Drop Down
Newbie
Newbie


Joined: 07 Jul 2017
Status: Offline
Points: 13
Post Options Post Options   Thanks (0) Thanks(0)   Quote arturk Quote  Post ReplyReply Direct Link To This Post Posted: 19 Dec 2017 at 6:38pm
On Z270 Gaming-ITX/ac after ME update HDCP 2.2 is not working anymore. Before update everything was OK! This means that after applying update we will lose possibility to watch on integrated graphics Netflix in 4k and play UHD BR movies.

Does anybody found fix for broken HDCP support? Motherboards with Z370 received Bios update fixing this issue, but as for now for Z270 there there is nothing new ...
Back to Top
 Post Reply Post Reply Page  <1 23456 13>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.281 seconds.