The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.
← Previous pageNext page →

    IMPORTANT SECURITY UPDATES!

    Discussion in 'Sager and Clevo' started by Prema, Nov 30, 2017.

  1. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    That file contains only MEI FW
     
    hmscott likes this.
  2. Papusan

    Papusan Jokebook's Sucks! Dont waste your $$$ on Filthy

    Reputations:
    42,742
    Messages:
    29,856
    Likes Received:
    59,714
    Trophy Points:
    931
    Prema and Vasudev like this.
  3. Chastity

    Chastity Company Representative

    Reputations:
    1,295
    Messages:
    6,545
    Likes Received:
    336
    Trophy Points:
    251
    I just finished updating my 1710 (PA71HS) with the latest Intel microcode they released on Jan 8. (Went from ver 5E to 80 for 7700HQ) and installed 16299.192. SpeculationControl shows that HW level protection is now enabled.
    microcode5eto80.jpg

    You can do this now using VMWare's Microcode updater driver. Or you can use UBU to modify a BIOS file with the correct extracted bin and flash that. (much more work)
     
    Last edited: Jan 10, 2018
    Prema, Vasudev and hmscott like this.
  4. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    Doesn't that remove Secure boot functionality? Because EFI Signing certificate is missed when you add custom menus and stuffs.
     
  5. raiden87

    raiden87 Notebook Evangelist

    Reputations:
    46
    Messages:
    341
    Likes Received:
    123
    Trophy Points:
    56
    I know that the files in the OP are for another vuln, but i thought that this thread was already hijacked for discussion about meltdown/spectre... so i asked about a "new" bios with updated microcode from prema :)
     
    Prema and Vasudev like this.
  6. hmscott

    hmscott Notebook Nobel Laureate

    Reputations:
    7,110
    Messages:
    20,384
    Likes Received:
    25,139
    Trophy Points:
    931
    Vasudev likes this.
  7. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    All PremaMods published this year (revisions showing 01/01/2018+) already have the new code. If you have an urgent need for it, I would suggest to just update the code in Windows manually or wait for MS to force it on you via one of their next updates.

    http://forum.notebookreview.com/threads/how-to-update-microcode-from-windows.787152/

    Again, this has nothing to do with the patch discussed in the OP!
     
    steberg, Georgel, ajc9988 and 2 others like this.
  8. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    I'll be updating the vmware ucode patcher in this thread. http://forum.notebookreview.com/thr...en-ht-on-laptops-pc-fix-is-here.806451/page-2
     
  9. Margarida Garcia

    Margarida Garcia Notebook Enthusiast

    Reputations:
    5
    Messages:
    11
    Likes Received:
    7
    Trophy Points:
    6
    Hello everyone,

    I have a P770ZM.

    This is my situation.

    Am I OK??

    Thanks
     

    Attached Files:

  10. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    Yours is invulnerable. Just update ME driver as per Papusan's post or use this direct link http://www.mediafire.com/file/6vgw43f777hf7ef/
     
    hmscott likes this.
  11. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    Georgel and hmscott like this.
  12. Margarida Garcia

    Margarida Garcia Notebook Enthusiast

    Reputations:
    5
    Messages:
    11
    Likes Received:
    7
    Trophy Points:
    6
    Vasudev likes this.
  13. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    Yes. Right click on that inf file and choose install.
     
  14. Anddo24

    Anddo24 Notebook Consultant

    Reputations:
    2
    Messages:
    117
    Likes Received:
    10
    Trophy Points:
    31
    Based on the OP. My test came back as vulnerable; model P65_67RSRP....Driver version 1.7.0.1057.

    As an edd user should I be worried?
     
  15. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    If it's vulnerable, simply run the patch. ;)
     
    KY_BULLET, Papusan and Vasudev like this.
  16. 5P4MB0T

    5P4MB0T Notebook Guru

    Reputations:
    24
    Messages:
    62
    Likes Received:
    30
    Trophy Points:
    26
    Thanks a lot, Prema!

    So once again the community here does the manufacturers/resellers' job...
     
    Prema and KY_BULLET like this.
  17. blacklord049

    blacklord049 Notebook Enthusiast

    Reputations:
    7
    Messages:
    46
    Likes Received:
    18
    Trophy Points:
    16
    So far so good on W65KJ1_KK1 system with your patch tool, BIOS 1.05.04 (feb 2017)
     
    Papusan, Prema, Vasudev and 1 other person like this.
  18. AndiiiHD

    AndiiiHD Notebook Consultant

    Reputations:
    4
    Messages:
    291
    Likes Received:
    60
    Trophy Points:
    41
    Here you can find the Bios version 1.05.08 (from my german reseller dubaro.de) - i did not flash it yet because i am moving into my new house next week and have no time to do updates at the moment ;-)
     
  19. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Just make sure to flash the patch from the OP again after any firmware update dated earlier than this year, as it'll be overwritten by regular Clevo update packages.
     
    Last edited: Jan 15, 2018
  20. blacklord049

    blacklord049 Notebook Enthusiast

    Reputations:
    7
    Messages:
    46
    Likes Received:
    18
    Trophy Points:
    16
    Even if I run the batch file inside the BIOS folder (not ALL folder) ?
     
  21. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Then it's not a stock Clevo update and you are fine. Clevo's own files flash everything.
    Other packages are only offered to re-seller.
     
    KY_BULLET likes this.
  22. blacklord049

    blacklord049 Notebook Enthusiast

    Reputations:
    7
    Messages:
    46
    Likes Received:
    18
    Trophy Points:
    16
    Well I don't know the official source of this BIOS package... so I don't want to risk anything now. My PC is working fine :)
    If anyone used the package feel free to give us a feedback!
     
  23. blacklord049

    blacklord049 Notebook Enthusiast

    Reputations:
    7
    Messages:
    46
    Likes Received:
    18
    Trophy Points:
    16
    Since the update the computer shutdowns when it's coming back from a long sleep (on lid opening). Don't know why... I saw an event saying "kernel power manager has initiated a shutdown transition" even if all my settings are set to "sleep". This is happening since the Intel ME update. Any idea ? Could it be related to ?

    A guy here has the same issue on a Windows 7 laptop :
    https://superuser.com/questions/107...after-powercfg-exe-hibernate-off-on-my-laptop

    I will check the events this afternoon to see if there is more info
     
    Last edited: Jan 16, 2018
  24. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    That's usually something when the battery level was too low at one point during the sleep state.
     
    Vasudev likes this.
  25. blacklord049

    blacklord049 Notebook Enthusiast

    Reputations:
    7
    Messages:
    46
    Likes Received:
    18
    Trophy Points:
    16
    My laptop was plugged in ;-)
     
  26. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Then IDK, this is usually the OS's job and not something the ME takes care off...maybe just toggle the settings with a full shut-down in-between.
     
  27. blacklord049

    blacklord049 Notebook Enthusiast

    Reputations:
    7
    Messages:
    46
    Likes Received:
    18
    Trophy Points:
    16
    Now that you're saying I had a similar issue a few days ago while playing a movie in Kodi.
    Kodi crashed then suddenly Windows was shutting down. It was before the Intel ME update.
    Settings are all set on : Sleep, in the control panel. Strange behavior then. It does not happen all the time of course. I've reset every parameter in the control panel and then set it back to the desired value. I'll see if it helps.
     
  28. Sptz

    Sptz Notebook Consultant

    Reputations:
    5
    Messages:
    144
    Likes Received:
    10
    Trophy Points:
    31
    Hi,

    I have a P650HP-G and even though I have the latest BIOS installed and also installed the latest Intel Management Engine driver, it still says it's vulnerable and detected IME to be version 11.8.50.3425

    Can anyone help?

    Thanks
     
  29. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    So Clevo's official update failed to patch it... :oops:
    Can you post a screenshot of that message?
     
    Vasudev likes this.
  30. Sptz

    Sptz Notebook Consultant

    Reputations:
    5
    Messages:
    144
    Likes Received:
    10
    Trophy Points:
    31
    Screenshot_2.png
     
    Vasudev likes this.
  31. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Your Security Version is on zero while it should be on 3.
    Try to uninstall and re-install the latest ME driver.
     
  32. Sptz

    Sptz Notebook Consultant

    Reputations:
    5
    Messages:
    144
    Likes Received:
    10
    Trophy Points:
    31
    I might've missed one thing though. Should I install the Tool from your website Prema? Or just the IME driver is enough?
     
  33. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    You can't use the Tool from the website because you have already updated by using Clevo's update. Power cycle the system (incl. un- and re-plugging power while it is off) and re-install the driver.
     
    Last edited: Jan 19, 2018
  34. Sptz

    Sptz Notebook Consultant

    Reputations:
    5
    Messages:
    144
    Likes Received:
    10
    Trophy Points:
    31
    Right, some weird stuff going on.

    So, I uninstalled IME, reinstalled, ran the scanner and it showed the correct IME version, and that it was patched and NOT vulnerable. Decided to reboot and see if anything changed and the exact same thing shows up in the screenshot I attached even though in Device Manager IME is still there with the correct latest version.
     
  35. Glzmo

    Glzmo Notebook Deity

    Reputations:
    476
    Messages:
    822
    Likes Received:
    86
    Trophy Points:
    41
    Thank you very much, @Prema ! What would the Clevo Community be without people like you that provide with free updates and mods that manufactuers either take ages to release or don't release at all? It's greatly appreciated!
     
    Vasudev, Papusan, Prema and 1 other person like this.
  36. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Don't worry it's patched. The reason you are seeing this inconsistency is that when using a manual driver installation method instead of the complete installer that the Intel Dynamic App service won't get installed.
     
    Vasudev, Papusan and KY_BULLET like this.
  37. idahosurge

    idahosurge Notebook Enthusiast

    Reputations:
    2
    Messages:
    36
    Likes Received:
    4
    Trophy Points:
    16
    Downloaded the ME_11_TOOL.zip and IZArc is asking for a password when I try to unzip the file.

    I have not a clue what the PW might be. I did try "admin", but that did not work.
     
  38. bigspin

    bigspin My Kind Of Place

    Reputations:
    632
    Messages:
    3,952
    Likes Received:
    566
    Trophy Points:
    181
    Thanx Prema. I think im OK!

    [​IMG]
     
    Vasudev likes this.
  39. steberg

    steberg Notebook Evangelist

    Reputations:
    248
    Messages:
    562
    Likes Received:
    461
    Trophy Points:
    76
    Password in OP.
     
    Vasudev likes this.
  40. idahosurge

    idahosurge Notebook Enthusiast

    Reputations:
    2
    Messages:
    36
    Likes Received:
    4
    Trophy Points:
    16
    Thanks steberg I found the PW.

    When updating my Clevo N130BU I get this in the error log:
    "Error 8704: Firmware update operation not initiated due to a SKU mismatch"
     
    steberg likes this.
  41. Vasudev

    Vasudev Notebook Nobel Laureate

    Reputations:
    12,050
    Messages:
    11,278
    Likes Received:
    8,816
    Trophy Points:
    931
    That's odd, I think you need to ask Prema. AFAIK, Prema has included all variants of MEI FW for easy patch.
     
  42. idahosurge

    idahosurge Notebook Enthusiast

    Reputations:
    2
    Messages:
    36
    Likes Received:
    4
    Trophy Points:
    16
    Vasudev likes this.
  43. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Careful man, better remove the link, as running that will brick almost all the other Clevo's, as they don't use the L&P version of the Management Engine.
     
    Vasudev and steberg like this.
  44. Mangix

    Mangix Notebook Guru

    Reputations:
    12
    Messages:
    69
    Likes Received:
    41
    Trophy Points:
    26
    Instead of doing this, is it possible to disable the ME completely by setting the HAP bit?
     
  45. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    I wouldn't stop the ME from loading (doing that is not actually disabling it) on a Windows based system.
     
  46. Mangix

    Mangix Notebook Guru

    Reputations:
    12
    Messages:
    69
    Likes Received:
    41
    Trophy Points:
    26
    Why not?
     
  47. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    Many Clevo's wouldn't even boot no more and the others would throw a ton of errors during runtime from sys-calls going into nowhere.
    Among other things you also loose the capability to overclock the BCLK...

    It's something you would do on a development system working in classified environment etc, but not on a gaming or benching system as it would harm the performance.
     
    Last edited: Jan 21, 2018
    Dennismungai and Vasudev like this.
  48. Mangix

    Mangix Notebook Guru

    Reputations:
    12
    Messages:
    69
    Likes Received:
    41
    Trophy Points:
    26
    Hrm weird,

    Some manufacturers like System76 (Clevo reseller) are already doing this along with neutering ME with me_cleaner. I've not heard of major issues.

    Although they are not really focused on overclocking.
     
  49. Prema

    Prema Your Freedom, Your Choice

    Reputations:
    9,368
    Messages:
    6,297
    Likes Received:
    16,486
    Trophy Points:
    681
    All S76 systems are designed for Linux and already use special firmware for that.
     
    Last edited: Jan 21, 2018
    Vasudev likes this.
  50. Mangix

    Mangix Notebook Guru

    Reputations:
    12
    Messages:
    69
    Likes Received:
    41
    Trophy Points:
    26
← Previous pageNext page →