Thanks for getting back to us!
Surface Studio Vulnerable to INTEL-SA-00086 Critical Security Vulnerability - Requires Microsoft to Issue a Firmware Update - How Long?
Intel released a disclosure today on a series of vulnerabilities in their management engine and trusted execution engine, affecting Surface Studio (and presumably other Surface devices).
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr
They included a tool to check to see if your system is vulnerable:
http://www.intel.com/sa-00086-support
I've run the tool on a Surface Studio and confirmed that is vulnerable and requires Microsoft to issue a firmware update with the patch Intel provided. As they have presumably already given the patch to you, I'm wondering how long you're going to leave us all vulnerable to this before you release the required firmware update to patch this?
We need this fixed ASAP!
Surface | Surface Studio | Safety and security
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
20 answers
Sort by: Oldest
-
Anonymous
2017-12-08T18:47:54+00:00 -
Anonymous
2017-12-08T18:57:37+00:00 There is two ways to connect USB to the Surface Pro 4 (you only specify "current Surface Devices"):
- Direct USB connection to the Surface Pro 4 tablet.
- Direct USB connection to the Surface Pro 4 docking station.
Intels tool still exhibits "vulnerable" - even after todays firmware updates to the components.
Sorry, but I believe Intel in this case (since you do NOT specify "Surface Pro 4" in your assurance).
If Intels tool is not to be trusted, then please explain why. And how we - as users - decide? In this case "blind trust" is not really a viable approach.
Please explain, why Microsoft - today - updated the Intel Management Engine from version 11.6.25.1229 (vulnerable according to Intel) to version 11.7.4.3330 (vulnerable according to Intel). See later in this thread.
Regards
-
Anonymous
2017-12-08T19:03:47+00:00 Thank you for getting back to the community! I want to emphasize that it is very important that this information was provided. While I understand that the assesment of these exploits can quite hard to do, I would appreciate it if security-related issues were addressed quicker in the future.
-
Anonymous
2017-12-08T19:04:33+00:00 Microsoft updated the Intel Management Engine version 11.6.25.1229 (vulnerable) today to version 11.7.4.3330 (still vulnerable according to Intels tool) on my Microsoft Surface Pro 4.
So... do we believe Intel or Microsoft?
I put my bets on Intel here...
Especially since Microsoft today issued firmware updates regarding this vulnerability. The only problem seems to be, that the system is also vulnerable after the update, that still lack any explanation (as well as the other firmware updates from today). Links lead to this:
Which really isn't that productive; nor assuring.
Regards
-
Anonymous
2017-12-11T08:15:00+00:00 Microsoft has investigated the issue and found the following:
- Local exploit of this vulnerability requires Direct Connect Interface (DCI) access via USB, which is not provided on Surface devices.
Does the Surface dock has a DCI Direct Connect Interface access via USB?
Is a Surface vurnable to this attack when connected to a Surface dock?