Join Sign in
0800 527 867
Contact us >
THE LAPTOP COMPANY LTD
  • Browse Range ˅
    • All of Government
    • Apple
    • Dell
    • Dynabook Toshiba
    • HP
    • Lenovo
    • Microsoft Surface
    • Education Shop
    • Work from Home gear
    • All Products
  • Solutions
    • AOG Government Agencies >
      • All of Government Product Catalogues
      • AoG Broader Outcomes
      • Gateway
    • Modernise Your Workforce with Surface >
      • Surface Pro for Business Copilot+ PC Intel
      • Surface Laptop for Business Copilot+ PC Intel
      • Surface Copilot Plus
      • Surface Pro Copilot Plus 5G
      • Surface Laptop 6
      • Surface Pro 10
      • Modernise Your Workforce
      • Surface Repairability
      • Surface Windows 11 Migration
      • Microsoft for Healthcare
      • Microsoft Design and Construction
      • Surface Broader Outcomes
      • Switch to Surface
    • NEW HP EliteBook G1 >
      • HP EliteBook X G1
      • HP EliteBook 8 G1
      • Choose Your EliteBook G11 >
        • HP EliteBook 1040 G11
        • HP EliteBook 800 G11
        • HP EliteBook 600 G11
    • Ctrl with HP >
      • Which HP ZBook G11?
      • HP ZBook Power G11
      • HP Windows 11 Migration
      • HP Carbon Offsets
      • HP Premium+ Support
      • HP Sustainability
      • HP Fleets
    • Apple with TLC
    • Financial Sector
    • Higher Education
    • Local Government
    • Meeting rooms
    • Hybrid Work
    • Schools and Students >
      • Smarter Classrooms
  • Services
    • Modern Fleet Mgmt
    • Procurement services
    • Fleet leasing
    • Windows 11 Migration
    • Intune & Device mgmt
    • Autopilot & Device Deployment
    • Jamf - Apple Mgmt
    • UXx User Experiences
    • RecoverMax - trade-ins
    • Renew - fix & re-use
  • Support
    • Get Support
    • Surface Repairs
    • Apple Repairs
    • About Us
    • Terms and Conditions >
      • Terms of Sale
      • Terms and Conditions of Service
      • Returns and Refunds
      • Privacy
  • Insights

Intel issues security alert for management firmware

24/11/2017

 
Intel has released a security alert for their management engine interface that is likely to affect all 6th, 7th, and 8th generation of their Core i series CPUs.

The summary of the problem that is outlined on Intel's website;
Intel® Management Engine (Intel® ME 11.0.0-11.7.0), Intel® Trusted Execution Engine (Intel® TXE 3.0), and Intel® Server Platform Services (Intel® SPS 4.0) vulnerability (Intel-SA-00086)

In response to issues identified by external researchers, Intel has performed an in-depth comprehensive security review of the following with the objective of enhancing firmware resilience:
  • Intel® Management Engine (Intel® ME)
  • Intel® Trusted Execution Engine (Intel® TXE)
  • Intel® Server Platform Services (SPS)
Intel has identified security vulnerabilities that could potentially impact certain PCs, servers, and IoT platforms.

Systems using Intel ME Firmware versions 11.0.0 through 11.7.0, SPS Firmware version 4.0, and TXE version 3.0 are impacted. You may find these firmware versions on certain processors from the:
  • 6th, 7th, and 8th generation Intel® Core™ Processor Family:
  • Intel® Xeon® Processor E3-1200 v5 and v6 Product Family
  • Intel® Xeon® Processor Scalable Family
  • Intel® Xeon® Processor W Family
  • Intel Atom® C3000 Processor Family
  • Apollo Lake Intel Atom® Processor E3900 series
  • Apollo Lake Intel® Pentium® Processors
  • Intel® Celeron® N and J series Processors

Intel has released a  downloadable tool that will help you discover whether your hardware is affected or not. Technical details are also available on their website.

Within the zip file download is a GUI tool, running the tool will result in a pass or fail on the vulnerability for the system you run it on.
Picture
Picture

OEM hardware manufacturers will be required to release firmware patches to resolve this issue.

For all of our hardware customers; we will be maintaining a set of links on this page for your reference.  If you require any support on this issue then please contact our support team or your account manager through your usual channels. ​For our ongoing SCCM support contract customers, we have already started the update management process and will liaise with you directly on performing updates as they become available.

The most up-to-date source for manufacturer's update links is on Intel's website directly;
Intel Management Engine Critical Firmware Update (Intel SA-00086)

Update 30/11/2017:

Direct OEM links to their specific information;
  • HP
  • Lenovo
  • Toshiba


Infineon TPM Vulnerability

2/11/2017

 
In Brief
Researchers have discovered a serious vulnerability in Infineon Trusted Platform Module (TPM) cryptographic processors used to secure encryption keys in many PCs, laptops, Chromebooks and smartcards.

In cryptographic terms, the flaw in the way the public key encryption key pair is generated makes it possible for an attacker to work out private 1024-bit and 2048-bit RSA keys stored on the TPM simply by having access to the public key.  This would allow an attacker to remove encryption or alter information otherwise protected by the keys stored on the TPM.

What is TPM?
A TPM is a cryptographic chip built on to the motherboard of many (but not all) PCs and laptops as a secure place to store system passwords, certificates, encryption keys and even biometric data (e.g. for fingerprint login or Windows Hello).  The principle is that storing keys inside the TPM is a lot better than keeping them on the hard drive or letting them be managed by the operating system, both of which can be compromised.

Microsoft’s BitLocker uses a TPM. They can also be used for authentication (checking a PC is the one it claims to be) and attestation (that a system’s boot image hasn’t been tampered with), for example on Google’s Chromebooks.

Remediation for Windows Devices
Step 1: Apply all Microsoft Windows Operating System Security Updates
Step 2: Determine devices in your organization that are affected using event log entries.
NOTE: After the applicable Windows update is applied, the system will generate Event ID 1794 in the Event Viewer after each reboot under Windows Logs - System when vulnerable firmware is identified. On devices running Windows 10 that have the October 2017 security update installed, in a CMD prompt, type "TPM.MSC" to open the Trusted Platform Module (TPM) Management snap-in. Devices with affected TPM modules will display the following error message: (Shown Below)
  • "The TPM is ready for use. The TPM firmware on this PC has a known security problem. Please contact your PC manufacturer to find out if an update is available. For more information please go to https://go.microsoft.com/fwlink/?linkid=852572."
  • If you determine that you do not have an Infineon® TPM capable system then no further action is required.
  • If your PC is affected, go to Step 3 below to locate your PC model and firmware availability. 
  • If your firmware is not yet available, Microsoft has provided the following mitigation process that is recommended until the release of the firmware update package.  
    • https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV170012
Step 3: Download and run the firmware update tool provided by the Hardware Vendor (Toshiba, HP, Lenovo, etc).
Step 4: Once the firmware update has been applied to vulnerable devices, additional steps may be required (e.g. devices where BitLocker is in use)

Links to firmware updates
The best source for up-to-date firmware links appears to be Infineon's website;
Information on TPM firmware update for Microsoft Windows
Direct manufacturer links from that page are;
  • HP
  • Lenovo
  • Toshiba

    The Laptop Company

    News and announcements

    Archives

    December 2019
    June 2019
    April 2019
    November 2018
    July 2018
    January 2018
    December 2017
    November 2017

    Contact Us
    x

      Contact us 

      Would you like to know more about these updates, or information about the services available from The Laptop Company?  For personal assistance during business hours, please call 0800 527 867.
    Send

.

Get in touch

About
Legal information
Contact
© COPYRIGHT THE LAPTOP COMPANY (LTD) 2022. ALL RIGHTS RESERVED.
Enquire >
Click here to Contact us
x
  • Browse Range ˅
    • All of Government
    • Apple
    • Dell
    • Dynabook Toshiba
    • HP
    • Lenovo
    • Microsoft Surface
    • Education Shop
    • Work from Home gear
    • All Products
  • Solutions
    • AOG Government Agencies >
      • All of Government Product Catalogues
      • AoG Broader Outcomes
      • Gateway
    • Modernise Your Workforce with Surface >
      • Surface Pro for Business Copilot+ PC Intel
      • Surface Laptop for Business Copilot+ PC Intel
      • Surface Copilot Plus
      • Surface Pro Copilot Plus 5G
      • Surface Laptop 6
      • Surface Pro 10
      • Modernise Your Workforce
      • Surface Repairability
      • Surface Windows 11 Migration
      • Microsoft for Healthcare
      • Microsoft Design and Construction
      • Surface Broader Outcomes
      • Switch to Surface
    • NEW HP EliteBook G1 >
      • HP EliteBook X G1
      • HP EliteBook 8 G1
      • Choose Your EliteBook G11 >
        • HP EliteBook 1040 G11
        • HP EliteBook 800 G11
        • HP EliteBook 600 G11
    • Ctrl with HP >
      • Which HP ZBook G11?
      • HP ZBook Power G11
      • HP Windows 11 Migration
      • HP Carbon Offsets
      • HP Premium+ Support
      • HP Sustainability
      • HP Fleets
    • Apple with TLC
    • Financial Sector
    • Higher Education
    • Local Government
    • Meeting rooms
    • Hybrid Work
    • Schools and Students >
      • Smarter Classrooms
  • Services
    • Modern Fleet Mgmt
    • Procurement services
    • Fleet leasing
    • Windows 11 Migration
    • Intune & Device mgmt
    • Autopilot & Device Deployment
    • Jamf - Apple Mgmt
    • UXx User Experiences
    • RecoverMax - trade-ins
    • Renew - fix & re-use
  • Support
    • Get Support
    • Surface Repairs
    • Apple Repairs
    • About Us
    • Terms and Conditions >
      • Terms of Sale
      • Terms and Conditions of Service
      • Returns and Refunds
      • Privacy
  • Insights