BIOS Update needed for Intel Vulnerability / Intel® Management Engine Critical Firmware Update

Options
haeusermannanna
haeusermannanna Member Posts: 2 New User
edited November 2023 in 2018 Archives
Hello everyone

According to the article listed below there is a Vulnerability in Intel processors. And this is a serious one. It would require Acer to provide BIOS Updates for a LOT of Laptops including VX15 / Predator / Aspire and so on. Even servers with XEON Chips  are affected and therefore no longer secure. This is not a fault of Acer but a fault of Intel. Yet Acer will have to provide BIOS Updates to close the Vulnerability.

https://www.theregister.co.uk/2017/11/20/intel_flags_firmware_flaws/

On the page listed below you can download a small program written by Intel to find out if your Intel CPU is affected.  For example: I own an Aspire VX 15 / 591G and I ran the small program and yes... unfortunately my Acer Aspire is affected by this vulnerability. This is bad! It leaves the CPU with an open backdoor through which hackers could potentially enter and take control without the installed Operating System realizing what, and that potentially something very bad is happening to the computer. 
https://www.intel.com/content/www/us/en/support/articles/000025619/software.html

I have at the moment the newest BIOS installed for the Aspire VX15 Version 1.06 But given the date of this BIOS  26/07/2017 This new Vulnerability might not be corrected yet.

ACER I need an answer from you urgently. Because only you can fix the mistake Intel made. Thank you very much.

Best Answers

  • ven98
    ven98 ACE Posts: 4,073 Pathfinder
    Answer ✓
    Options
    https://us.answers.acer.com/app/answers/detail/a_id/51890

    This is list of some affected devices. You can keep an eye on this page as it gets update from time to time. Unfortunately BIOS 1.06 won't fix sa-00086 vulnerability and when there is a new update fixing that, it will be displayed on this page.
    Always post the following characterisitcs of the device:
    -Model number
    -Part number(not required, but helpful)
    -CPU
    -GPU
    -Operating system

    Helios 300 and Nitro 5 users DO NOT update the BIOS to version 1.22 if you don't want the keyboard's backlight to turn off after 30 seconds even when the device is plugged in.


    Hit 'Like' if you find the answer helpful!   
    Click on 'Yes' if the comment answers your question!

  • Jose-Acer
    Jose-Acer Administrator Posts: 1,339 Community Administrator
    Answer ✓
    Options
    Hello @haeusermannanna,

    We are working to provide updates for all models impacted by this vulnerability. Acer is working closely with Intel to address the situation and are working to release firmware updates to fix the security vulnerability. You can find a list of the affected Acer models here:

    Intel Security Vulnerabilities Regarding Intel® Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE)

    This list is constantly being updated to add the newest fixes when they become available.

Answers

  • ven98
    ven98 ACE Posts: 4,073 Pathfinder
    Answer ✓
    Options
    https://us.answers.acer.com/app/answers/detail/a_id/51890

    This is list of some affected devices. You can keep an eye on this page as it gets update from time to time. Unfortunately BIOS 1.06 won't fix sa-00086 vulnerability and when there is a new update fixing that, it will be displayed on this page.
    Always post the following characterisitcs of the device:
    -Model number
    -Part number(not required, but helpful)
    -CPU
    -GPU
    -Operating system

    Helios 300 and Nitro 5 users DO NOT update the BIOS to version 1.22 if you don't want the keyboard's backlight to turn off after 30 seconds even when the device is plugged in.


    Hit 'Like' if you find the answer helpful!   
    Click on 'Yes' if the comment answers your question!

  • Jose-Acer
    Jose-Acer Administrator Posts: 1,339 Community Administrator
    Answer ✓
    Options
    Hello @haeusermannanna,

    We are working to provide updates for all models impacted by this vulnerability. Acer is working closely with Intel to address the situation and are working to release firmware updates to fix the security vulnerability. You can find a list of the affected Acer models here:

    Intel Security Vulnerabilities Regarding Intel® Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE)

    This list is constantly being updated to add the newest fixes when they become available.
  • haeusermannanna
    haeusermannanna Member Posts: 2 New User
    Options
    Thank you very much for answering me so quickly. I am happy to report that I could update my Acer V5-591G tonight and that there is only one computer left which is not patched yet. And this is Intels fault!

    I highly appreciate your help and the links provided. Without your help I would have never found the information on my own.

    Kathrin
  • Ed1420
    Ed1420 Member Posts: 1 New User
    Options
    I have an Acer AXC-603 which is a desktop not on the affected list, but I am having the problem.  Windows 10 tells me to update the driver, which I cannot do. I get the message that the latest driver is installed.  Is the list of affected models still being updated?  Today is December 12, 2018.