Intel Management Engine Issue INTEL-SA-00086 Fix |
Post Reply | Page 123 13> |
Author | |||
parsec
Moderator Group Joined: 04 May 2015 Location: USA Status: Offline Points: 4996 |
Post Options
Thanks(0)
Posted: 25 Nov 2017 at 2:18pm |
||
Fix for the Intel Management Engine Firmware Vulnerability Security Issue INTEL-SA-00086
Links to Intel's statement and description of the issue: https://security-center.intel.com/ https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr The link to ASRock's page for information on the affected Intel 100 and 200 series chipset boards, downloading the appropriate version of the tools, and instructions for using the IME Firmware update tools can be found below. Please read the instructions carefully and download only the correct version for your board's chipset. UPDATE: If you have an ASRock Intel 300 series chipset board (Z370), the IME firmware update will be provided in a UEF/BIOS update. A link to a page with links to the ASRock Z370 chipset board's UEFI/BIOS download pages is provided on the page below. https://www.asrock.com/microsite/2017IntelFirmware/ There are two versions of the IME Firmware update tools package, ME1 and ME2. The ME1 version download package file is ME-consumer_11.8.50.3425.zip The ME2 version download package file is ME-corporate_11.8.50.3425.zip The ME-corporate version is only for use with the business-oriented chipsets. All the 'Z' series chipset boards use the ME1 version. The ASRock download page for the tools has a table with the chipsets that must use the ME2 version. All other affected chipsets use the ME1 version. Within each version download are two tools, one to run in a Windows 64 bit OS installation, the other to run from a DOS bootable USB flash drive, for Windows 32 bit and other OS types. You only need to run one of these tools, from one version. There is no need to run both tools, or use both versions of the tools. The IME firmware update process has two steps. First the IME firmware update tool is run, and then the PC MUST be restarted to complete the process. When complete, the IME firmware version is: 11.8 Build 3425 Hotfix 50. I ran the ME1 version, Windows64\UPDATEME64 tool on my ASRock Z270 Gaming K6 board. It completed fine, restarted the PC, done within a few minutes. Edited by parsec - 06 Dec 2017 at 11:43am |
|||
beard55
Newbie Joined: 26 Nov 2017 Status: Offline Points: 3 |
Post Options
Thanks(1)
|
||
I followed the instructions to run ME1 (ran as administrator). The cmd window went so fast I couldn't see the result, but after rebooting the Intel diagnostic still reported the vulnerability and the bios is still reported as P7.10. The MB is a ASRock Fatal1ty Z170 Gaming-ITX ac.
So.... Still waiting for a new bios to resolve the issue.
|
|||
Atma
Newbie Joined: 26 Nov 2017 Status: Offline Points: 5 |
Post Options
Thanks(1)
|
||
The ME1 Package doesn't work on the ASRock X299 Taichi. I get an SKU mismatch error.
Error 8704: Firmware update operation not initiated due to a SKU mismatch
|
|||
parsec
Moderator Group Joined: 04 May 2015 Location: USA Status: Offline Points: 4996 |
Post Options
Thanks(0)
|
||
The CMD window disappeared because the program never ran, because you ran it in Admin mode. It is reasonable to assume using Admin mode would be correct, but in this case it won't work. I did not use Admin mode when I ran it on my ASRock Z170 board, and it ran fine. It takes a minute or so to complete, so just double click the file to run it. |
|||
parsec
Moderator Group Joined: 04 May 2015 Location: USA Status: Offline Points: 4996 |
Post Options
Thanks(0)
|
||
The SKU mismatch message is caused by your processor apparently not matching an affected processor. The SKU code of your processor was apparently not found. What processor are you using? The newest Intel High End Desktop (HEDT) processors, also called the X-Series, may not be included in this firmware update. I can't tell from Intel's information page if all of them are. Some definitely are. Also while the list of affected chipsets includes the Intel 200 series, the X-series chipsets are many times excluded from the mainstream/performance chipsets. Usually Intel would specifically identify the X-series chipsets like the X299 as separate from the other 200 series chipsets. Intel's information is ambiguous about this. |
|||
OrpheusXx
Newbie Joined: 26 Nov 2017 Status: Offline Points: 2 |
Post Options
Thanks(0)
|
||
Downloaded the ME1 update from Asrock, followed the instructions, but it returned an error:
" Error 8771: Invalid File. " in the error.txt. Edited by OrpheusXx - 26 Nov 2017 at 6:16pm |
|||
Kloba12345
Newbie Joined: 26 Nov 2017 Status: Offline Points: 1 |
Post Options
Thanks(0)
|
||
It does not work on Z170 Gaming K4 with i7 7700K
Error 8746: Firmware update not initiated due to invalid image length EDIT: Now it worked.
Edited by Kloba12345 - 27 Nov 2017 at 12:24am |
|||
Atma
Newbie Joined: 26 Nov 2017 Status: Offline Points: 5 |
Post Options
Thanks(0)
|
||
I'm using an Core i7-7820X. According to the Intel Tool I'm affected: Edited by Atma - 26 Nov 2017 at 9:30pm |
|||
hoisdom
Newbie Joined: 27 Nov 2017 Status: Offline Points: 6 |
Post Options
Thanks(0)
|
||
parsec
Moderator Group Joined: 04 May 2015 Location: USA Status: Offline Points: 4996 |
Post Options
Thanks(0)
|
||
That's strange, the update program, FWUpdLcl64, is supplied by Intel, and is the same program used by other mother board manufactures. I don't know why you would get an SKU mismatch. It seems you have the INF/Chipset files installed, since the Risk Assessment tool is able to identify your processor. Unless each program uses a different method of processor identification. All I can do is report this to ASRock. |
|||
Post Reply | Page 123 13> |
Tweet
|
Forum Jump | Forum Permissions You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |