ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - Intel Management Engine vulnerability SA-00086
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

Intel Management Engine vulnerability SA-00086

 Post Reply Post Reply Page  <1 23456 8>
Author
Message
soulstealer View Drop Down
Newbie
Newbie
Avatar

Joined: 30 Sep 2016
Location: Hon
Status: Offline
Points: 76
Post Options Post Options   Thanks (0) Thanks(0)   Quote soulstealer Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 4:08am
just flashed it.

C:\Users\xxx\Downloads\ME-corporate_11.8.50.3425\ME-corporate_11.8.50.3425\Windows64>FWUpdLcl64 -f FW.bin

Intel (R) Firmware Update Utility Version: 11.8.50.3425
Copyright (C) 2007 - 2017, Intel Corporation.  All rights reserved.

Communication Mode: MEI
Checking firmware parameters...

Warning: Do not exit the process or power off the machine before the firmware update process ends.
Sending the update image to FW for verification:  [ COMPLETE ]



FW Update:  [ 100% (-)]Do not Interrupt
FW Update is completed successfully.

rebooting and hoping to see you again.

note: rebooted and installed latest ime/atm drivers and everything went butter smooth. will test tools again.

tools show not vulnerable anymore, system runs perfectly.

mission accomplished.

id say it is safe to use, but you are on your own risk.

if you notice i have chosen to flash the corporate image and use corporate drivers on a consumer board, but i did that to just in case have everything updated there is and show how cool asrock is (and me).

these are the files i used with windows 10, i7 7700k and asrock h170 fataliy performance (default edition, not d3, not hyper):

http://asrock.pc.cdn.bitgravity.com/TSD/ME-corporate_11.8.50.3425.zip (this is from asrock support, and so its official)

http://www.station-drivers.com/index.php?option=com_remository&Itemid=352&func=startdown&id=3195&lang=en (is rather not official, but contains an intel license, station-drivers is deemed legit and ive used it myself)


Edited by soulstealer - 24 Nov 2017 at 4:56am
Back to Top
OFelix View Drop Down
Newbie
Newbie


Joined: 18 Sep 2015
Status: Offline
Points: 22
Post Options Post Options   Thanks (0) Thanks(0)   Quote OFelix Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 4:38am

Hi ASRock,

please release a statement and when a fix is available please host it on your own servers.

Thanks
Back to Top
Zjenep View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 20
Post Options Post Options   Thanks (0) Thanks(0)   Quote Zjenep Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 4:20pm
Official statement from ASRock:
https://www.asrock.com/microsite/2017IntelFirmware/


Edited by Zjenep - 24 Nov 2017 at 5:53pm
Back to Top
Arukado_ View Drop Down
Newbie
Newbie


Joined: 22 Nov 2017
Status: Offline
Points: 12
Post Options Post Options   Thanks (0) Thanks(0)   Quote Arukado_ Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 4:59pm
Originally posted by Zjenep Zjenep wrote:

Official statement from ASRock:
http://https://www.asrock.com/microsite/2017IntelFirmware/


So I think that Asrock is not taking this case seriously.
JZ admit that you have something to do with this site.

For example:
Quote
If your model Intel 100/200/300 series but not in the following list, please download ME1 package


My english is poor but this is just hilarious and I'm quite sure that nobody from Asrock wrote that.

Next thing is image resolution ffs. Really 13KB and 470x270???
And photos of dos flash tool taken with cell phone i think under strange angle ;)

And finally links to ME1 and ME2 packages still hosted on non Asrock domain which in my opinion anybody can replace with some malicious software.

ME1 link
http://asrock.pc.cdn.bitgravity.com/TSD/ME-consumer_11.8.50.3425.zip

ME2 link
http://asrock.pc.cdn.bitgravity.com/TSD/ME-corporate_11.8.50.3425.zip

Is it so god damn hard for Asrock officials to made a proper solution and host it on their own servers? Is it to much responsibility?

Really looking on how this whole thing is spinning I'm quite sure that with that kind of customer service I'll never buy Asrock product again.
Maybe that's only my opinion but seriously I'm working in It industry for over twelve years by now and I'm not seeing that kind of
stopgap often.

Ps. Zjenep you joined this forum 33 minutes ago how did you get this link? There's no information on Asrock main page not in news section not i technical support? Google says nothing about that either.
Back to Top
Zjenep View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 20
Post Options Post Options   Thanks (0) Thanks(0)   Quote Zjenep Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 5:19pm
I happen to have an ASRock motherboard which is affect by the Intel bug as well. I was in contact with ASRock support already and they sent me the link. I just wanted to share it with the rest of you, so I just registered on the forum.

The links look legit to me. The use the same content delivery network from Bitgravity to offer drivers and such. Have a look at the download options for Asia and US:
https://www.asrock.com/mb/Intel/Z170M%20Extreme4/%3Fcat=Download&os=Win1064

I agree with Arukado, picture quality could be better :)
Back to Top
Arukado_ View Drop Down
Newbie
Newbie


Joined: 22 Nov 2017
Status: Offline
Points: 12
Post Options Post Options   Thanks (0) Thanks(0)   Quote Arukado_ Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 5:32pm
Originally posted by Zjenep Zjenep wrote:

I happen to have an ASRock motherboard which is affect by the Intel bug as well. I was in contact with ASRock support already and they sent me the link. I just wanted to share it with the rest of you, so I just registered on the forum.


So you have Z170M Extreme4 right? Same mobo as mine. Did you flash it already?
Can you paste us the whole email from asrock?

For the bitgravity you're actually right. I've never used Asia or USA links cos I'm from Europe so I didn't noticed that they hosting it on external servers.

Right now I'm just curious since it looks like they have a patch already so they have to be aware of the problem why ffs nobody from Asrock came here and told us anything.
Why there's no info in news or technical section?
Why it looks like something that was written on the knee in a rush.
Why they not paste it in mobos download section? Asus did that a while ago.

Many questions and zero answers so imho communication is very very bad.


Back to Top
Montoya View Drop Down
Newbie
Newbie
Avatar

Joined: 01 Feb 2016
Status: Offline
Points: 26
Post Options Post Options   Thanks (0) Thanks(0)   Quote Montoya Quote  Post ReplyReply Direct Link To This Post Posted: 24 Nov 2017 at 9:18pm
Looks very unprofessional and suspicious what Asrock has come up with for their customers with affected products, providing a link that is nowhere referenced on main page, news page or support pages....

Looks like Asus is the only one my shopping list, for replacing my old Z170 mainboard, because they prove right now, to handle security issues professionally, like it always should be !!!


Edited by Montoya - 24 Nov 2017 at 9:23pm
Fatal1ty Z170 Gaming-ITX/ac, Intel i5-6500, Kingston HyperX Fury 16GB, Samsung 950 Pro 512GB, Fractal Design Core 500, Win10 Pro X64
Back to Top
lex23 View Drop Down
Newbie
Newbie


Joined: 25 Nov 2017
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote lex23 Quote  Post ReplyReply Direct Link To This Post Posted: 25 Nov 2017 at 12:17am
Can someone help me please?

I use a ASRock Z170 Extreme4 and installed the ME-consumer_11.8.50.3425 update.

Now my PC doesn't completely shut down anymore. Monitor turns off, but the computer/fans keep going.

Help please!
Back to Top
SDeath View Drop Down
Newbie
Newbie


Joined: 08 Oct 2017
Status: Offline
Points: 5
Post Options Post Options   Thanks (0) Thanks(0)   Quote SDeath Quote  Post ReplyReply Direct Link To This Post Posted: 25 Nov 2017 at 12:24am
I tried to install the update on my Fatal1ty X299 Professional Gaming i9 but I get a SKU mismatch?
The Intel tool showed me I was volnurable so I'd like to be patched.

PS I downloaded the ME1 package.


Edited by SDeath - 25 Nov 2017 at 8:23pm
Back to Top
flashback8 View Drop Down
Newbie
Newbie


Joined: 24 Nov 2017
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote flashback8 Quote  Post ReplyReply Direct Link To This Post Posted: 25 Nov 2017 at 1:51am
Originally posted by soulstealer soulstealer wrote:

Originally posted by flashback8 flashback8 wrote:

Hello. FYI, the Intel ME update seems to break playback of Ultra HD Blu-Ray discs. I own the Fatal1ty Z370 Gaming-ITX/ac board, which is one of the few out there that can handle all the ridiculous requirements for playing UHD discs. Among other things, the Intel ME drivers are a critical part of the puzzle since they enable SGX support, which UHD discs require.

Anyway, everything was fine until I installed the updated ME drivers. Now, Cyberlink's software tells me that HDCP 2.2 (a handshake protocol over HDMI) is no longer available. I figured that I might be able to get it working again if I reinstalled Intel's graphics drivers and restarted the PC. Nope. Same issue. I need to double check the UEFI settings but I'm 99% sure nothing changed.

Has anybody else had this problem? Any workarounds? I'll keep tinkering and will report back if anything changes.

Thank you.

ill probably update firmware and drivers in an hour or so. where did you get your drivers and firmware update from?

Hi. I got the files from the BigGravity link posted here. I didn't download until it had been confirmed that the files were legit.

In any event, are you saying that you're able to confirm whether or not HDCP 2.2 handshakes can still occur? If so, that'd be great! I'd like to find out if this is a consistent issue or if I'm just unlucky.

Quote
i want to add that intel recommends a certain uninstall routine, but for mainstream users it should not be important.


Okay. I missed that. I went back and tried to do it. I wasn't allowed to do any of that. Not sure if it's because I had already installed the update, or didn't have a password for unprovisioning, or what. Oh well.
Back to Top
 Post Reply Post Reply Page  <1 23456 8>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.142 seconds.