Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

9821

November 21st, 2017 08:00

URGENT - Intel Management Engine - critical security flaw

Intel has major security flaws in the Management Engine. You need to read the Intel emergency memo from a few hours ago. In the memo, Intel links a tool to check if your system is vulnerable. Right now neither Dell nor Intel has posted updated software to remedy this critical issue for the XPS 9560 or 9550.

https://www.intel.com/content/www/us/en/support/articles/000025619/software.html

4 Operator

 • 

14K Posts

November 21st, 2017 10:00

Lol, ok then.  Well if this is how you feel about security vulnerabilities that Intel has acknowledged and is committing to fix, then I can't wait to see your reaction to the other news that broke about Intel Management Engine last week, which they might NOT fix because "it's not a security vulnerability, it's a feature": thenextweb.com/.../

16 Posts

November 21st, 2017 08:00

Intel® Management Engine Critical Firmware Update (Intel SA-00086)

Last Reviewed: 20-Nov-2017

Article ID: 000025619

16 Posts

November 21st, 2017 09:00

Don't shoot the messenger.

Regardless, this needs to be sorted yesterday.

4 Operator

 • 

14K Posts

November 21st, 2017 09:00

Do you understand how updates work?  That security advisory was originally released YESTERDAY, and it doesn't even indicate that INTEL has developed a fix for this yet.  That will probably take a while, especially because security-related code is typically harder to write correctly than "regular" code in order to avoid introducing new bugs.  And then AFTER Intel develops the fix, they have to provide it to OEMs like Dell and others so they can roll that fix into their own BIOS updates.  Then THOSE updates need to be tested internally to make sure nothing else breaks.  If you've been around these forums for a while, you may be aware that some recent BIOS updates have had some adverse side effects like destabilizing USB device connectivity through Dell docks or even wiping out a system's boot device list, rendering it unbootable.  Obviously customers would prefer that things like that don't happen.

Bottom line: The fact that a fix may be critically important to have does not automatically make it possible to deliver right away.  Even if every engineer that would have to be involved with this dropped everything else they were doing to work on this, it would STILL take some amount of time, certainly more than a day especially given that Dell can't do anything until Intel does.

1 Message

November 21st, 2017 14:00

Here Dell lists affected systems and says BIOS releases are now available for download from here.

64 Posts

November 21st, 2017 18:00

We apologize for the inconvenience, but this service is temporarily unavailable. Please try again later. message for Dell statement about intel.

4 Operator

 • 

754 Posts

November 22nd, 2017 02:00

Here is the Dell statement (for client/consumer systems) on the matter. It will be updated as and when further information is available.

4 Operator

 • 

754 Posts

November 22nd, 2017 06:00

Yes, there is here.

1 Message

November 22nd, 2017 06:00

Is there a similar response for the enterprise/server side of things?

1 Message

November 22nd, 2017 23:00

My laptop Latitude E5470 was originally listed in the Dell statement but later on has been removed from the list. Running the Intel-SA-00086 Detection Tool it clearly states that my system is vulnerable.

Does this mean that Dell will not issue a fix for my laptop?

4 Operator

 • 

754 Posts

November 24th, 2017 01:00

Hi etal,

I'm looking into why the E5470 was removed from the list and I'll provide an update as soon as I hear back.

4 Posts

November 26th, 2017 09:00

I have a similar question.   The Latitude E6410 is not included on the Dell list of affected systems.   Does this mean it is not affected, or just that there is no plan for it to receive an update?   I ran the Intel SA-00086 detection tool, but the results were:  

Detection Error:  This system may be vulnerable.  

November 26th, 2017 11:00

The INTEL-SA-00086 Detection tool says my Dell Inspiron 15 7579 is vulnerable.

It isn't listed in the Dell statement here: http://www.dell.com/support/article/us/en/19/sln308237/dell-client-statement-on-intel-me-txe-advisory--intel-sa-00086-?lang=en

When will this be addressed?

4 Posts

November 28th, 2017 22:00

Why is Alienware 17 R3 not on the list, when R2 and R4 are on it, and it's a Skylake CPU?

The Intel tool says that my Alienware 17 R3 is affected.

4 Operator

 • 

754 Posts

November 29th, 2017 03:00

Hi guys,

jburktx - The E6410 is not an affected system so isn't on the list.

etal, elprice7345 and HunterZ0 - I've requested an update from engineering as to why your systems don't appear on the list.

I'll post an update as soon as I can.

Thanks

No Events found!

Top