cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
chip9
Fanfold Paper
Posts: 3
Registered: ‎11-23-2017
Location: LT
Views: 2,562
Message 11 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

I still waiting for a fix 

 

Admin note; subject edited

deadnull
Paper Tape
Posts: 2
Registered: ‎11-27-2017
Location: CA
Views: 2,359
Message 12 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

When can we expect a Fix for the Y700? I have seen https://support.lenovo.com/ca/en/solutions/len-17297 and it is not listed but the system is vulnerable. This is according to the Intel-SA-00086 Detection Tool found here https://www.intel.com/content/www/us/en/support/articles/000025619/software.html image attached.Untitled.jpg

 

Admin Edit: merged in and edited subject.

martin1001
Paper Tape
Posts: 1
Registered: ‎11-27-2017
Location: AT
Views: 2,314
Message 13 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

same here, i'm affected too

 

Admin Edit: merged in and edited subject.

Allnight
Blue Screen Again
Posts: 1
Registered: ‎11-27-2017
Location: US
Views: 2,318
Message 14 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

I have a Yoga 910 13IKB-80vf IdeaPad and when I run the tool from Intel (Intel SA-00086 detection tool), it tells me that it is vulnerable to LEN-17297

 

I've been looking all over the Lenovo site and can't find mention of this machine being vulnerable or not (I know that it is, courtesy of Intel), and the newest firmware (BIOS/UEFI updates) I see is dated 2017-06-15.

 

Is there an ETA on a fix for this vulnerability?

 

Admin note; post merged in, subject edited.

przemek1234pl
802.11n
Posts: 149
Registered: ‎11-28-2017
Location: PL
Views: 2,401
Message 15 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

Will Lenovo release a fix for critical vulnerabilities in Intel Management Engine for my Lenovo Yoga 500-14ISK? I have not found it on the official Lenovo list, but Intel's tool says it's vulnerable. I have Intel ME firmware version 11.0.0.1197 and it's a Skylake version of this Yoga notebook. It's still on warranty.

 

There is not my notebook:

https://support.lenovo.com/pl/pl/product_security/len-17297

 

Admin note; post merged in, subject edited.

mgm12000
What's DOS?
Posts: 1
Registered: ‎11-28-2017
Location: US
Views: 2,332
Message 16 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

So I've run Intel's vulnerability detection tool on my laptop and it says this model (700-14ISK, model 80QD) is vulnerable. I've searched the Lenovo Security Advisory LEN-17297 but my laptop isn't listed at all let alone have an update to download.

 

I've also looked up all downloads available for my laptop on it's support page and I did run the BIOS update available - however, after the update was completed, I ran the Intel tool again and it says the system is still vulnerable.

 

When will a security update for this issue be available or where can I find it?

Thanks,

-Matt

 

Admin note; post merged in, subject edited.

Mikk3lRo
What's DOS?
Posts: 1
Registered: ‎11-28-2017
Location: DK
Views: 2,251
Message 17 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

Same story here.

 

Admin Edit: merged in and edited subject.

masneyb
Paper Tape
Posts: 3
Registered: ‎11-09-2016
Location: US
Views: 2,318
Message 18 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

On the page https://support.lenovo.com/us/en/product_security/len-17297, the Yoga 910 13IKB is not listed as one of the laptops that will receive this security update. Intel's test tool at https://downloadcenter.intel.com/download/27150 confirms that this laptop is vulnerable. Can someone at Lenovo add the 910 to the list of laptops that will be updated?

 

Admin note; post merged in, subject edited. 13IKB added in body

UniqueUserName
What's DOS?
Posts: 1
Registered: ‎11-29-2017
Location: US
Views: 2,223
Message 19 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

Same here. 

 

It seems very strange (maybe just an oversight?) that is isn't listed at all.

 

Admin Edit: merged in and edited subject.

deadnull
Paper Tape
Posts: 2
Registered: ‎11-27-2017
Location: CA
Views: 2,183
Message 20 of 40

Re: Intel Manageability Engine Firmware 8.x/9.x/10.x/11.x- security vulnerabilities

@UniqueUserName wrote:

Same here. 

 

It seems very strange (maybe just an oversight?) that is isn't listed at all.

 


I mean it is possible that it is was just an oversight. Hopefully this post brings attention to it. Sadly it requires a firmware patch so there is not much we can do as end users. 

 

Admin Edit: merged in and edited subject.