ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - Intel Management Engine Issue INTEL-SA-00086 Fix
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

Intel Management Engine Issue INTEL-SA-00086 Fix

 Post Reply Post Reply Page  <1 89101112 13>
Author
Message Reverse Sort Order
BWolf View Drop Down
Newbie
Newbie


Joined: 17 Dec 2017
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote BWolf Quote  Post ReplyReply Direct Link To This Post Posted: 17 Dec 2017 at 1:07pm
Did anyone find a fix for Error 8719: Firmware update cannot be initiated because Local Firmware update is disabled yet?

I have a Z170 Gaming K4.
Waiting now for 1 month and no new patches seem to come out that fix this, very unsettling.
Back to Top
Krautmaster View Drop Down
Newbie
Newbie


Joined: 28 Nov 2017
Status: Offline
Points: 22
Post Options Post Options   Thanks (0) Thanks(0)   Quote Krautmaster Quote  Post ReplyReply Direct Link To This Post Posted: 14 Dec 2017 at 10:46pm
waiting for somthing flashable for my x299 i9 prof gaming + i9 7980 XE.


The provided one wants to do a downgrade from 

C:\Users\kraut\Downloads\ME-consumer_11.8.50.3425\ME-consumer_11.8.50.3425\Windows64>FWUpdLcl64.exe -fwver

Intel (R) Firmware Update Utility Version: 11.8.50.3425
Copyright (C) 2007 - 2017, Intel Corporation.  All rights reserved.

FW Version: 11.10.0.1287

------------

the Intel check tool stucks with all drivers and win fresh setup

C:\Users\kraut\Downloads\SA00086_Windows\SA00086_Windows\DiscoveryTool>Intel-SA-00086-console.exe

Unbehandelte Ausnahme: System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
   bei System.Security.Principal.NTAccount.Translate(IdentityReferenceCollection sourceAccounts, Type targetType, Boolean forceSuccess)
   bei System.Security.Principal.NTAccount.Translate(Type targetType)
   bei System.Security.AccessControl.CommonObjectSecurity.ModifyAccess(AccessControlModification modification, AccessRule rule, Boolean& modified)
   bei System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(AccessRule rule)
   bei DiscoveryTool.FileExtractor.Extract(String directoryName, Boolean localization)
   bei DiscoveryTool.CLI.Program.Main(String[] args)


Edited by Krautmaster - 14 Dec 2017 at 10:47pm
Back to Top
GTwannabe View Drop Down
Newbie
Newbie


Joined: 12 Dec 2017
Status: Offline
Points: 5
Post Options Post Options   Thanks (0) Thanks(0)   Quote GTwannabe Quote  Post ReplyReply Direct Link To This Post Posted: 12 Dec 2017 at 3:17am
Tag for info on IME patch.
Back to Top
Natanji View Drop Down
Newbie
Newbie
Avatar

Joined: 20 Dec 2016
Status: Offline
Points: 8
Post Options Post Options   Thanks (0) Thanks(0)   Quote Natanji Quote  Post ReplyReply Direct Link To This Post Posted: 10 Dec 2017 at 9:17am
Hi, I just discovered (by using Intel's testing tool) that my Asrock J3455M is also affected. But I can't see which of these is the correct version (ME1 or ME2) for me to download when I have an Apollolake board? Or are you still working on a patch for that one?

Quote INTEL-SA-00086 Detection Tool
Copyright(C) 2017, Intel Corporation, All rights reserved

Application Version: 1.0.0.146
Scan date: 2017-12-10 01:07:20 GMT

*** Host Computer Information ***
Name: <confidential>
Manufacturer: To Be Filled By O.E.M.
Model: To Be Filled By O.E.M.
Processor Name: Intel(R) Celeron(R) CPU J3455 @ 1.50GHz
OS Version:    (4.14.3-1-ARCH)

*** Intel(R) ME Information ***
Engine: Intel(R) Trusted Execution Engine
Version: 3.0.2.1108
SVN: 1

*** Risk Assessment ***
Based on the analysis performed by this tool: This system is vulnerable.
Explanation:
The detected version of the Intel(R) Trusted Execution Engine firmware
  is considered vulnerable for INTEL-SA-00086.
  Contact your system manufacturer for support and remediation of this system.


PS: Is it really not possible to log on to this board here with HTTPS? Feels kinda bad to send my password in the open...


Edited by Natanji - 10 Dec 2017 at 9:22am
Back to Top
Truman View Drop Down
Newbie
Newbie


Joined: 05 Dec 2017
Status: Offline
Points: 4
Post Options Post Options   Thanks (0) Thanks(0)   Quote Truman Quote  Post ReplyReply Direct Link To This Post Posted: 09 Dec 2017 at 11:10am
I am using an Intel Core i7-7800X
Back to Top
Kladno View Drop Down
Newbie
Newbie


Joined: 15 Aug 2016
Status: Offline
Points: 34
Post Options Post Options   Thanks (1) Thanks(1)   Quote Kladno Quote  Post ReplyReply Direct Link To This Post Posted: 08 Dec 2017 at 5:17am
Yes, I know how to install it and today there is a 'new' version without any 'classified' files, only 3.56 MB.

Back to Top
rico View Drop Down
Newbie
Newbie


Joined: 23 Nov 2017
Status: Offline
Points: 30
Post Options Post Options   Thanks (0) Thanks(0)   Quote rico Quote  Post ReplyReply Direct Link To This Post Posted: 07 Dec 2017 at 6:58am
Intel(R) ME Firmware ICC Tools User Guide.pdf:

Quote
Intel® Management Engine Firmware Integrated Clock Controller (ICC) Tool
 
Tools User Guide
January 2017
Revision 0.5
 
Intel Confidential


lol. whoops. In fact, I'm not even sure that whole /Tools folder should even be in there :)

In any case, this download isn't just for Kaby Lake. It's also applicable to my Skylake system on Z170 Gaming K6+ but I've already been running these ME drivers for the last week: http://forum.asrock.com/forum_posts.asp%3FTID=6667&PID=40181&title=intel-management-engine-vulnerability-sa00086#40181

To install new device drivers (not firmware!) just run any of the setup apps in the Installers folder. They're all the same and you end up with driver v11.7.0.1045 running Intel Management Engine Interface under System devices (Device Manager).


Back to Top
Kladno View Drop Down
Newbie
Newbie


Joined: 15 Aug 2016
Status: Offline
Points: 34
Post Options Post Options   Thanks (0) Thanks(0)   Quote Kladno Quote  Post ReplyReply Direct Link To This Post Posted: 07 Dec 2017 at 3:51am
Hi,

on the web for Asrock Extreme 7+/Z170/Skylake


I found today a new file:

Intel Management Engine driver ver:11.7.0.1045 12/6/2017 142.85MB

This file contains many files and seems to be just for Kaby Lake,
not Skylake, and I can not find any readme or instructions.

Although the name claims 11.7 inside are files like ME_11.8_Consumer_C0_LP.bin.
Also in folder 'HDCP Wireless Rx' certificates for HDCP.

But unfortunately I'm not sure how to work with it.


Edited by Kladno - 07 Dec 2017 at 4:28am
Back to Top
apoisonedgift View Drop Down
Newbie
Newbie


Joined: 04 Dec 2017
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote apoisonedgift Quote  Post ReplyReply Direct Link To This Post Posted: 06 Dec 2017 at 3:15pm
Originally posted by parsec parsec wrote:

Originally posted by apoisonedgift apoisonedgift wrote:

I've just been getting the error:

Error 8771: Invalid File. 

Intel's tool says my system is vulnerable... not really sure what else to do now?

Edit: I have a B150M-Pro4


If you received an error message, the IME firmware update did not happen.

Which update tool are you using? For a B150 chipset board, you should be using the ME2 firmware update package. The error message of Invalid File seems to indicate that is the case.

https://www.asrock.com/microsite/2017IntelFirmware/

Ah yeah that was it, thank you! Previously the page didn't quite make much sense to me, so either they updates it or I was just having a dumb moment when I looked at it. I was under the impression ME2 was for corporate motherboards, and assumed that mine was a consumer board - thus it was not the case. Thanks for your help - all patched and sorted now according to the discovery tool :)
Back to Top
parsec View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 May 2015
Location: USA
Status: Offline
Points: 4996
Post Options Post Options   Thanks (0) Thanks(0)   Quote parsec Quote  Post ReplyReply Direct Link To This Post Posted: 06 Dec 2017 at 11:42am
Originally posted by Truman Truman wrote:

Thanks Parsec. I'll keep an eye out on the Asrock website for updates. Maybe they'll post something if/when Intel issues a more complete fix.


Thanks for your patience! ASRock can only provide what they are given by Intel, so all we can do is depend on Intel in this situation.

Important question for you, what Intel processor are you using? An Intel document that is available includes the 7th Gen X-Series Intel® CoreTM Processors in the list of those included in the IME firmware update tool. That may not make sense given your experience with the tool.

If you can let us know which Intel processor you are using, perhaps we can sort this out better for you and everyone.

Back to Top
 Post Reply Post Reply Page  <1 89101112 13>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.133 seconds.