On May 1st 2017, Intel published a security advisory regarding a firmware vulnerability in certain systems that utilize Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM) or Intel® Small Business Technology (SBT). The vulnerability could enable a network attacker to remotely gain access to business PCs or devices that use these technologies.
There is an escalation of privilege vulnerability in Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 that can allow an unprivileged attacker to gain control of the manageability features provided by these products. This vulnerability does not exist on Intel-based consumer PCs with consumer firmware, Intel servers utilizing Intel® Server Platform Services (Intel® SPS), or Intel® Xeon® Processor E3 and Intel® Xeon® Processor E5 workstations utilizing Intel® SPS firmware.
There are two ways this vulnerability may be accessed, please note that Intel® Small Business Technology is only vulnerable to the second method:
Severe.
Our customer's security is paramount, to that end Stone are working with key vendors to provide firmware updates which close this vulnerability as quickly as possible. Those updates will be able available to download from this article as soon as they are made available to us
Intel has released a discovery tool which will analyse your systems for the vulnerability.
Actions:
1. Determine if you have an Intel® AMT, Intel® SBA, or Intel® ISM capable systems. If you determine that you do not have an Intel® AMT, Intel® SBA, or Intel® ISM capable system then no further action is required.
2. Utilize the INTEL-SA-00075 Detection Guide to assess if your system has the impacted firmware.
3. Stone highly recommends updating affected systems Management Engine (ME) firmware as soon as they become available. Please review the affected products section of this article for ME firmware update availability.
4. If a firmware update is not yet available, mitigations are provided by the INTEL-SA-00075 Mitigation Guide. It is recommended that unpatched systems should have the steps detailed in the mitgation guide applied to them until such time as an ME firmware update becomes available.
The issue has been observed in Intel manageability firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 for Intel® Active Management Technology, Intel® Small Business Technology, and Intel® Standard Manageability. Versions before 6 or after 11.6 are not impacted.
Where possible, updated BIOSes or patches for Management Engine Firmware are shown below. This article will be updated as more BIOSes or patches become available.
StonePC Lite/Tower / All In One
Product code / General BIOS Update Link |
Motherboard model |
Updated ME Download |
BOAMOT-458 | Asus P8B75-M |
(Asus Ivybridge) Windows Patch: 8.1.x.3608 |
BOAMOT-461 | Asus P8Q77-M | |
Asus B85M-E |
(Asus Haswell) Windows Patch: 9.1.41.3024 (updated 29/6/17 with improved update utility) DOS Patch: 9.1.41.3024 |
|
Asus CS-B |
||
Asus Q87T |
||
Asus Q87M-E |
||
Asus B150M-A |
(Asus Skylake / Kaby Lake) Windows Patch: 11.6.27.3264 DOS Patch: 11.6.27.3264 |
|
Asus Q170M-C |
||
Asus Q170T |
||
Asus B150M-A/M.2 |
||
Asus B250M-A | ||
Asus Q270M-C |
||
ISRMOT-174 | Gigabyte MW50-SV0 |
(Gigabyte C612 Xeon Workstation) BIOS R06 with patched Workstation / HEDT ME Firmware. |
Legacy Desktop Products
Stock code |
Motherboard model |
Patched ME firmware |
DQ57TM |
Windows Patch: 6.2.61.3635 |
|
DQ67SW |
Windows Patch: 7.1.91.3272 | |
DQ67OW |
||
DQ67EP |
||
DQ77MK |
Windows Patch: 8.1.71.3708 |
|
DB75EN |
||
DQ77CP |
||
DQ77KB |
Further information regarding Intel’s release schedule for their own branded desktop products can be found here.
StonePC Micro
Stock code |
Kit model |
Motherboard model |
Patched ME firmware |
INTNUC-10007 |
DC53427HYE |
D53427RKE |
Windows BIOS: 8.1.71.3608 |
INTNUC-10009 |
NUC5i5MYHE |
NUC5i5MYBE |
Windows BIOS: 10.0.55.3000 |
Stone Notebooks
Chassis Part Code |
Notebook Model |
Patched ME firmware |
NT310 |
Not currently available, please follow mitigating actions. |
|
NT310 |
Applies to:
Asus B150M-A/M.2 |