EVGA

Z390 DARK i9-9900k CSME still vulnerable?

Author
Self-Hoisted-Patard
New Member
  • Total Posts : 2
  • Reward points : 0
  • Joined: 2022/10/30 21:57:46
  • Status: offline
  • Ribbons : 0
2022/10/31 07:34:54 (permalink)
Hello, 
 
Please forgive me if I should’ve posted this question under the bios v110 sticky. I wasn’t sure if the thread was open for comments as there hasn’t been any new info in some time... 


I’m a long time lurker here, and have had no issues with 3 generations of EVGA Nvidia cards and I am an proud z390 DARK owner.

My current setup Is Z390 DARK v1.0 bios-v110, i9-9900k at 5.2 allcore vcore override @ 1.25vcore -25vdroop , EK aio 360mm rad, 2x 8gb single stack ripjaws 5 ddr4 b-die 3600 16.16.16.36 @ 4200 16.16.16.36 1.500v , EVGA 3090 FTW 3 Ultra Gaming 
2x 256gb Samsung nvme ssds raid zero setup in RST oprom. Just upgraded to Win 11 home from 10 Home edition.


I’ve taken the CSME vulnerability seriously since it was first reported almost 5 years ago. I‘ve always patched vulns asap and religiously.
 
Upon installing win 11, I did a clean install downloaded win11 22h2 multi version direct from MS and Rufus’d a USB installer. Ran the EVGA drivers from my driver usb with all the most recent drivers available here from EVGA as always. No issues with install everything runs great…. Stability tests ran fine, DARK board still solid as a rock. But alas… first series of windows updates and there is a new Intel chipset/FW update. I halted it and went to Intel for info and checked back here to see if I had missed an update. Nay… 
 
Intel notes appear fine. I installed as recommended, finished all security and cumulative updates. Started getting comfortable with new OS , configured pwsh w/ fancy choco Posh bash going through new setup scripts etc etc…  I noticed an intel log from my LAN driver install saying one of the Intel drivers was rejected as it does not meet security standards by Win Defender. But nothing seems out of the ordinary. Device manager shows all hardware installed, no missing LAN drivers. Looking through the rest of the Intel logs I was confused by the new chipset driver as it’s actually stamped as generic mostly for xenon chips. I checked my PCH version in bios and confirmed it shows latest version which is still same update revision listed here by EVGA, checked 9900k microcode versions no new changes. Intel FW upgrade from win11 didn’t seem to change anything so just to double check I ran the Intel CSME vuln detector and it failed.  

It instructed me to get the most current updates available to which Intel had just installed, My system has always had the latest ME patches and MS security updates.

Unless I’ve missed something somewhere, I thought this platform was fully patched and secured from the ME issues. Does anyone else by chance get the same vulnerable status from the Intel checker? I‘ve never actually run the check for vulnerabilities with the Intel tool since I’ve regularly installed updates for this since they’ve been release.
 
Am I running faulty ground truth circuits in my wetware? Was the Intel tool always going to read vulnerable even after years of patches?
Did Windows 11 break the ME patches or exposed new vulnerabilities with CSME? My Google fu is pretty strong but I can’t find anything but the same search loops and dead ends with same old topics and posts about these issues. Which is why I finally came to ask the experts ( not redditors ) …. Is everything cool with these conditions? Should I run back to Win10 and wait?
Do all my base belong to some one !?! 


 
Much appreciation & thanks to whomever with which this finds concern.


 
 
 
 

Hamlet; “For ’tis the sport to have the engineer Hoist with his own petard.” to which spoke Rosencrantz;
“Yes, Gildenstern… I know I've misspelled petard… I know, I know!?!” --A drunken bard probably
#1

3 Replies Related Threads

    usbarlow@hotmail.com
    Superclocked Member
    • Total Posts : 104
    • Reward points : 0
    • Joined: 2006/05/23 23:05:27
    • Status: offline
    • Ribbons : 0
    Re: Z390 DARK i9-9900k CSME still vulnerable? 2022/11/01 13:51:31 (permalink)
    Two things.
    1. You Rufus's a usb installer of win 11? Why when there is a media creator through microsoft?
     
    2. I always hesitate to let window update any driver unless there is an issue.. I would roll back to a previous state or uninstall the driver and reinstall the EVGA version.
    #2
    Self-Hoisted-Patard
    New Member
    • Total Posts : 2
    • Reward points : 0
    • Joined: 2022/10/30 21:57:46
    • Status: offline
    • Ribbons : 0
    Re: Z390 DARK i9-9900k CSME still vulnerable? 2022/11/02 10:32:15 (permalink)
    Rufus is a tried and true usb boot tool. It’s an open source community project you can look through every line of code if you choose. I’ve used it for years and as far as writing bootable usb drives it’s absolutely the best option on a windows platform. 
    Also  I like to check hash for iso files,  not just hope the installer did a good job. 


    And my question was if anyone else who has this board and cpu combo here after being
     
    -fully patched with bios v110- 
     
    After running the intel CSME tool have it come back as vulnerable? I was just wanting to cross off my diag list if it’s just me and I have something to fix or if everyone else has the same results and to ask why does it still read vulnerable?
     
     
     

    Hamlet; “For ’tis the sport to have the engineer Hoist with his own petard.” to which spoke Rosencrantz;
    “Yes, Gildenstern… I know I've misspelled petard… I know, I know!?!” --A drunken bard probably
    #3
    xuqi99
    New Member
    • Total Posts : 41
    • Reward points : 0
    • Joined: 2015/04/30 07:06:29
    • Location: Australia
    • Status: offline
    • Ribbons : 3
    Re: Z390 DARK i9-9900k CSME still vulnerable? 2022/11/29 06:16:48 (permalink)
    The latest release BIOS has Intel ME firmware 12.0.85.1869v9.1
    https://forums.evga.com/BIOS-Updates-for-Z390-Dark-110-Z390-FTW-111-m3511899.aspx
     
    The latest Intel ME release for the Z390 chipset is; 12.0.92.2145
     
    Mitigated the following security vulnerabilities: INTEL-TA-00610 (IPU 2022.3) - CVE-2022-26845; CVE-2022-27497; CVE-2022-29893; CVE-2021-33159; CVE-2022-29466; CVE-2022-29515
     
    https://station-drivers.c...5-and-5Mo)/lang,en-us/
    #4
    Jump to:
  • Back to Mobile