Flaws found in Intel Management Engine (ME), TXE and SPS

Page 6 of 20 FirstFirst ... 4567816 ... LastLast

  1. Posts : 7,901
    Windows 11 Pro 64 bit
       #50

    I have a Gigabyte GA-Z77X-UD5H motherboard with a i5-3570K CPU. The Intel tool says my system is not at risk. However, Gigabyte has just released a new BIOS F16j for this 2012 motherboard which says "Adjust MATS table to improve OS compatibility". Does this relate to the Intel vulnerability or something else?
      My Computers


  2. Posts : 2,832
    Windows 10 Pro X64
       #51

    Hi,
    @Steve C : That has nothing to do with this vulnerability.

    Cheers,
      My Computers


  3. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #52

    Steve C said:
    I have a Gigabyte GA-Z77X-UD5H motherboard with a i5-3570K CPU. The Intel tool says my system is not at risk. However, Gigabyte has just released a new BIOS F16j for this 2012 motherboard which says "Adjust MATS table to improve OS compatibility". Does this relate to the Intel vulnerability or something else?
    fdegrove said:
    Hi,
    @Steve C : That has nothing to do with this vulnerability.

    Cheers,
    Information on VBS & MATS: Virtualization-based Security (VBS) | Microsoft Docs

    And if you really want to understand how it all comes together(send everyone away, make a large pot of coffee, and have fun(?)reading and following all the links): Mitigate threats by using Windows 10 security features (Windows 10) | Microsoft Docs
      My Computers


  4. Posts : 5,478
    2004
       #53

    Cliff S said:
    And if you really want to understand how it all comes together(send everyone away, make a large pot of coffee, and have fun(?)reading and following all the links): Mitigate threats by using Windows 10 security features (Windows 10) | Microsoft Docs
    Isn't the point that this runs underneath Windows (or Linux or any other OS you are running).

    There is not really any point reading about mitigations MS may have done if your system is compromised before Windows even loads.

    Windows (or any other OS) is unaware of what IME is doing. Just see the first post in this thread.

    Please don't think me a tin foil hatted loon (I'm not) but surely Intel baking a separate CPU and OS running under and before any OS you install is something to be mildly concerned about. Especially if its (undisclosed) functionality isn't documented at all and then turns out to be vulnerable.
      My Computer


  5. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #54

    lx07 said:
    Isn't the point that this runs underneath Windows (or Linux or any other OS you are running).

    There is not really any point reading about mitigations MS may have done if your system is compromised before Windows even loads.

    Windows (or any other OS) is unaware of what IME is doing. Just see the first post in this thread.

    Please don't think me a tin foil hatted loon (I'm not) but surely Intel baking a separate CPU and OS running under and before any OS you install is something to be mildly concerned about. Especially if its (undisclosed) functionality isn't documented at all and then turns out to be vulnerable.
    Even the developer of Minix(the OS that's used for IME) was surprised.
    http://www.cs.vu.nl/~ast/intel/

    Andrew S. Tanenbaum, Professor at the Vrije Universiteit
      My Computers


  6. Posts : 2,075
    Windows 10 Pro
       #55

    Please don't think me a tin foil hatted loon (I'm not) but surely Intel baking a separate CPU and OS running under and before any OS you install is something to be mildly concerned about. Especially if its (undisclosed) functionality isn't documented at all and then turns out to be vulnerable.
    Exactly.....point in fact. Remember the Lenovo HDD with the embedded firmware reporting to the NSA. Not a tinfoil hatted loon.....not at all.
      My Computer


  7. Posts : 29,078
    Windows 10 21H1 Build 19043.1023
       #56

    Cliff S said:
    By the way, some PC owners, those with "Off the shelf" PCs, like laptops, workstations, and so on, might not even get the needed BIOS update.

    A good example, my Lenovo H530, that originally came with Windows 8.1, hasn't had a BIOS/UEFI update since NOV 17th, 2016, and most drivers hav't been updated(from Lenovo) in there last 2 years either.
    So don't be surprised if the OEMs have stopped supporting your equipment.
    Yep! My Lenovo Intel Lappy is a 14" Flex 4-1470 and isn't even mentioned in Lenovo's list of affected computers. The first one listed is the Flex 5-1470, and nope, that wasn't a typo on their part.

    So, I'm not sure what I should do.
      My Computer


  8. Posts : 170
    Win 10 Pro 2004
       #57

    Wynona said:
    Yep! My Lenovo Intel Lappy is a 14" Flex 4-1470 and isn't even mentioned in Lenovo's list of affected computers. The first one listed is the Flex 5-1470, and nope, that wasn't a typo on their part.

    So, I'm not sure what I should do.
    See Lenovo's Intel ME 11.x, SPS 4.0, and TXE 3.0 Cumulative Security Update list.
      My Computers


  9. Posts : 29,078
    Windows 10 21H1 Build 19043.1023
       #58

    Thanks, Xips! I checked yesterday and my Flex 4-1470 wasn't there. They must have updated the list whilst I was sleeping. Which is good. Now I just have to wait until tomorrow. Maybe.
      My Computer


  10. Posts : 14,046
    Windows 11 Pro X64 22H2 22621.1848
       #59

    I have a Lenovo K450 which has a Intel 4th gen processor. Intel says it's not vulnerable, Lenovo says it's not vulnerable and the tools says it's not vulnerable, so I'm A-okay.
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 07:11.
Find Us




Windows 10 Forums