Surface Studio Vulnerable to INTEL-SA-00086 Critical Security Vulnerability - Requires Microsoft to Issue a Firmware Update - How Long?

Anonymous
2017-11-21T00:42:36+00:00

Intel released a disclosure today on a series of vulnerabilities in their management engine and trusted execution engine, affecting Surface Studio (and presumably other Surface devices). 

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr

They included a tool to check to see if your system is vulnerable:

http://www.intel.com/sa-00086-support

I've run the tool on a Surface Studio and confirmed that is vulnerable and requires Microsoft to issue a firmware update with the patch Intel provided. As they have presumably already given the patch to you, I'm wondering how long you're going to leave us all vulnerable to this before you release the required firmware update to patch this?

We need this fixed ASAP!

Surface | Surface Studio | Safety and security

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

20 answers

Sort by: Most helpful
  1. Anonymous
    2017-12-08T18:46:01+00:00

    Hi everyone, 

    Microsoft is aware of the Intel Management Engine vulnerability (Intel-SA-00086). The Intel vulnerability detection tool currently lists Microsoft Surface devices as vulnerable to this security advisory.

    Microsoft has investigated the issue and found the following:

    1. Remote exploit of this vulnerability requires Intel Active Management Technology (AMT). Current Surface devices do not allow remote connectivity to the ME because our devices do not run AMT.
    2. Local exploit of this vulnerability requires Direct Connect Interface (DCI) access via USB, which is not provided on Surface devices.

    Because of this, we believe exploits using this vulnerability are significantly reduced on Surface devices. We care deeply about ensuring our devices are reliable and secure and are working with Intel to generate fixes for current devices, which we expect to release in the near future.

    Thanks,

    Greg

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2017-12-11T20:46:14+00:00

    Thank you for your answer Greg, and if what you say here is official word from Microsoft, you really need to make a msdn / general blog post and have Intel link it here: https://www.intel.com/content/www/us/en/support/articles/000025619/software.html under the Resources for system/motherboard manufacturers, probably with the title "Microsoft Surface" so people don't get confused and think it applies to Windows in general.

    If you don't, then users are going to start attempting firmware bypasses and adjustments that could brick their devices.

    While I appreciate the answer, this took you nearly two and a half weeks to post after the story was picked up.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2017-11-23T23:16:18+00:00

    My Surface Pro 4 was found to be vulnerable as well. When will we get a fix for this vulnerability? Other major PC manufactures have a software patch in the works to be released soon on their PC lines and I would think Microsoft would be right there with them. I bought a Surface Pro because I thought it was a superior tablet but if you don't back it to fix major security vulnerabilities found in the software or hardware used by your products then it is not better then the competition.

    We need a fix Microsoft and we we need it ASAP!

    Was this answer helpful?

    0 comments No comments
  4. Barb Bowman 80,805 Reputation points MVP Volunteer Moderator
    2017-11-22T13:06:54+00:00

    I'm pretty sure that SP4 and anything released after SP4 is vulnerable.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-11-22T00:59:27+00:00

    Just ran the tool on a Surface Pro 4 and it was found to be vulnerable as well.

    Was this answer helpful?

    0 comments No comments