Intel Management Engine vulnerability SA-00086 |
Post Reply | Page <1 23456 8> |
Author | ||
soulstealer
Newbie Joined: 30 Sep 2016 Location: Hon Status: Offline Points: 76 |
Post Options
Thanks(0)
|
|
just flashed it.
C:\Users\xxx\Downloads\ME-corporate_11.8.50.3425\ME-corporate_11.8.50.3425\Windows64>FWUpdLcl64 -f FW.bin Intel (R) Firmware Update Utility Version: 11.8.50.3425 Copyright (C) 2007 - 2017, Intel Corporation. All rights reserved. Communication Mode: MEI Checking firmware parameters... Warning: Do not exit the process or power off the machine before the firmware update process ends. Sending the update image to FW for verification: [ COMPLETE ] FW Update: [ 100% (-)]Do not Interrupt FW Update is completed successfully. rebooting and hoping to see you again. note: rebooted and installed latest ime/atm drivers and everything went butter smooth. will test tools again. tools show not vulnerable anymore, system runs perfectly. mission accomplished. id say it is safe to use, but you are on your own risk. if you notice i have chosen to flash the corporate image and use corporate drivers on a consumer board, but i did that to just in case have everything updated there is and show how cool asrock is (and me). these are the files i used with windows 10, i7 7700k and asrock h170 fataliy performance (default edition, not d3, not hyper): http://asrock.pc.cdn.bitgravity.com/TSD/ME-corporate_11.8.50.3425.zip (this is from asrock support, and so its official) http://www.station-drivers.com/index.php?option=com_remository&Itemid=352&func=startdown&id=3195&lang=en (is rather not official, but contains an intel license, station-drivers is deemed legit and ive used it myself)
Edited by soulstealer - 24 Nov 2017 at 4:56am |
||
OFelix
Newbie Joined: 18 Sep 2015 Status: Offline Points: 22 |
Post Options
Thanks(0)
|
|
Hi ASRock, please release a statement and when a fix is available please host it on your own servers. Thanks
|
||
Zjenep
Newbie Joined: 24 Nov 2017 Status: Offline Points: 20 |
Post Options
Thanks(0)
|
|
Official statement from ASRock:
https://www.asrock.com/microsite/2017IntelFirmware/ Edited by Zjenep - 24 Nov 2017 at 5:53pm |
||
Arukado_
Newbie Joined: 22 Nov 2017 Status: Offline Points: 12 |
Post Options
Thanks(0)
|
|
So I think that Asrock is not taking this case seriously. JZ admit that you have something to do with this site. For example:
My english is poor but this is just hilarious and I'm quite sure that nobody from Asrock wrote that. Next thing is image resolution ffs. Really 13KB and 470x270??? And photos of dos flash tool taken with cell phone i think under strange angle ;) And finally links to ME1 and ME2 packages still hosted on non Asrock domain which in my opinion anybody can replace with some malicious software. ME1 link http://asrock.pc.cdn.bitgravity.com/TSD/ME-consumer_11.8.50.3425.zip ME2 link http://asrock.pc.cdn.bitgravity.com/TSD/ME-corporate_11.8.50.3425.zip Is it so god damn hard for Asrock officials to made a proper solution and host it on their own servers? Is it to much responsibility? Really looking on how this whole thing is spinning I'm quite sure that with that kind of customer service I'll never buy Asrock product again. Maybe that's only my opinion but seriously I'm working in It industry for over twelve years by now and I'm not seeing that kind of stopgap often. Ps. Zjenep you joined this forum 33 minutes ago how did you get this link? There's no information on Asrock main page not in news section not i technical support? Google says nothing about that either. |
||
Zjenep
Newbie Joined: 24 Nov 2017 Status: Offline Points: 20 |
Post Options
Thanks(0)
|
|
I happen to have an ASRock motherboard which is affect by the Intel bug as well. I was in contact with ASRock support already and they sent me the link. I just wanted to share it with the rest of you, so I just registered on the forum.
The links look legit to me. The use the same content delivery network from Bitgravity to offer drivers and such. Have a look at the download options for Asia and US: https://www.asrock.com/mb/Intel/Z170M%20Extreme4/%3Fcat=Download&os=Win1064 I agree with Arukado, picture quality could be better :) |
||
Arukado_
Newbie Joined: 22 Nov 2017 Status: Offline Points: 12 |
Post Options
Thanks(0)
|
|
So you have Z170M Extreme4 right? Same mobo as mine. Did you flash it already? Can you paste us the whole email from asrock? For the bitgravity you're actually right. I've never used Asia or USA links cos I'm from Europe so I didn't noticed that they hosting it on external servers. Right now I'm just curious since it looks like they have a patch already so they have to be aware of the problem why ffs nobody from Asrock came here and told us anything. Why there's no info in news or technical section? Why it looks like something that was written on the knee in a rush. Why they not paste it in mobos download section? Asus did that a while ago. Many questions and zero answers so imho communication is very very bad. |
||
Montoya
Newbie Joined: 01 Feb 2016 Status: Offline Points: 26 |
Post Options
Thanks(0)
|
|
Looks very unprofessional and suspicious what Asrock has come up with for their customers with affected products, providing a link that is nowhere referenced on main page, news page or support pages.... Looks like Asus is the only one my shopping list, for replacing my old Z170 mainboard, because they prove right now, to handle security issues professionally, like it always should be !!!
Edited by Montoya - 24 Nov 2017 at 9:23pm |
||
Fatal1ty Z170 Gaming-ITX/ac, Intel i5-6500, Kingston HyperX Fury 16GB, Samsung 950 Pro 512GB, Fractal Design Core 500, Win10 Pro X64
|
||
lex23
Newbie Joined: 25 Nov 2017 Status: Offline Points: 1 |
Post Options
Thanks(0)
|
|
SDeath
Newbie Joined: 08 Oct 2017 Status: Offline Points: 5 |
Post Options
Thanks(0)
|
|
flashback8
Newbie Joined: 24 Nov 2017 Status: Offline Points: 9 |
Post Options
Thanks(0)
|
|
Hi. I got the files from the BigGravity link posted here. I didn't download until it had been confirmed that the files were legit. In any event, are you saying that you're able to confirm whether or not HDCP 2.2 handshakes can still occur? If so, that'd be great! I'd like to find out if this is a consistent issue or if I'm just unlucky.
Okay. I missed that. I went back and tried to do it. I wasn't allowed to do any of that. Not sure if it's because I had already installed the update, or didn't have a password for unprovisioning, or what. Oh well. |
||
Post Reply | Page <1 23456 8> |
Tweet
|
Forum Jump | Forum Permissions You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |