While I understand MS's stance on this, I find it comical that my old Gigabyte H170 chipset motherboard which should long ago have been abandoned by the manufacturer got patched for this just recently, while my Surface Pro 2017 and Surface Book (1st gen) are still technically (even if unlikely to be exploited) vulnerable.
Surface Studio Vulnerable to INTEL-SA-00086 Critical Security Vulnerability - Requires Microsoft to Issue a Firmware Update - How Long?
Intel released a disclosure today on a series of vulnerabilities in their management engine and trusted execution engine, affecting Surface Studio (and presumably other Surface devices).
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr
They included a tool to check to see if your system is vulnerable:
http://www.intel.com/sa-00086-support
I've run the tool on a Surface Studio and confirmed that is vulnerable and requires Microsoft to issue a firmware update with the patch Intel provided. As they have presumably already given the patch to you, I'm wondering how long you're going to leave us all vulnerable to this before you release the required firmware update to patch this?
We need this fixed ASAP!
Surface | Surface Studio | Safety and security
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
20 answers
Sort by: Most helpful
-
Anonymous
2017-12-21T22:42:33+00:00 -
Anonymous
2017-12-15T08:06:58+00:00 - Local exploit of this vulnerability requires Direct Connect Interface (DCI) access via USB, which is not provided on Surface devices.
Thanks for posting the same statement on all these topics but could you please answer this question:
- Are there other ports that could provide DCI access on the surface?
- Does the surface dock has a USB with DCI or does the surface dock has other ports with DCI
- Is there a way, vurnability to turn a normal usb in to one with DCI access.
-
Barb Bowman 80,805 Reputation points MVP Volunteer Moderator2017-12-12T11:19:51+00:00 > you really need to make a msdn / general blog post
-
Anonymous
2017-12-11T22:25:12+00:00 Thanks for the response, Greg. I appreciate the update.
I look forward to the firmware update and will leave this question as unanswered until the required firmware patch is released. Please continue to keep us posted.
-
Anonymous
2017-12-11T08:15:00+00:00 Microsoft has investigated the issue and found the following:
- Local exploit of this vulnerability requires Direct Connect Interface (DCI) access via USB, which is not provided on Surface devices.
Does the Surface dock has a DCI Direct Connect Interface access via USB?
Is a Surface vurnable to this attack when connected to a Surface dock?