Microsoft updated the Intel Management Engine version 11.6.25.1229 (vulnerable) today to version 11.7.4.3330 (still vulnerable according to Intels tool) on my Microsoft Surface Pro 4.
So... do we believe Intel or Microsoft?
I put my bets on Intel here...
Especially since Microsoft today issued firmware updates regarding this vulnerability. The only problem seems to be, that the system is also vulnerable after the update, that still lack any explanation (as well as the other firmware updates from today). Links lead to this:
Which really isn't that productive; nor assuring.
Regards