Revision : 04 -------------------------------------------------------------------------------- Software Name Intel AMT 4.1 - Management Engine Firmware Support models ThinkPad R400 - IEEE 1394 models Machine types and models: 7438-P1x,P2x,T1x,T2x,T3x,T4x,T6x,T7x,T8x,T9x,TAx,TBx,TCx 7439-11x,12x,13x,14x,15x,16x,17x,18x,19x,1Ax,1Bx,1Cx,1Dx, 1Ex,1Fx,1Gx,1Hx,1Jx,1Kx,1Lx,1Mx,1Nx,1Px,1Rx,1Sx,1Tx, 1Ux,1Vx,1Wx,E1x,E2x,E3x,E4x,P1x,P2x,P3x,P4x,P5x,P6x, P7x,P8x,P9x,PAx,PBx,PCx,T1x,V1x,V2x,V3x,V4x,V5x 7440-11x,12x,V1x,V5x,T1x 7440-1Nx 7443-P1x,P2x,P3x,P4x,P5x,P7x,PAx,PBx,PCx,PDx,PEx,PFx,PGx, S6x,S7x,11x,S8x,S9x,SAx,SBx,SCx,SDx,SEx,SFx,T4x,T5x, T6x,T7x,T8x,T9x,TAx,TBx,TCx,TDx,TEx,TFx,TGx,THx,TJx, TKx,TLx,TMx,TNx,TPx,TRx,TSx,1Tx,TUx 7445-11x,12x,13x,14x,15x,16x,17x,18x,19x,1Ax 7446-X1x 7447-X2x 2782-P1x,P2x,P3x,P4x,P5x,P6x,P7x,P8x,P9x,T1x,T2x,PAx,PBx, T5x,T6x,T7x,T8x,T9x,TKx,TLx,TMx,TNx,TPx,TRx,TSx,1Tx, TUx,TVx,TWx,TYx,TZx,S1x,S2x,S3x,S4x 2783-T1x,T2x 2784-11x,12x,13x,14x,V1x,V3x 2786-11x,12x,13x,14x,V1x 2787-21x,22x,23x,26x,27x,28x,P1x,P2x,P3x,P4x,P5x 2788-X3x 2789-X4x ThinkPad T400, T400s ThinkPad T500 ThinkPad W500 ThinkPad W700, W700ds ThinkPad X200, X200s, X200 Tablet ThinkPad X301 Operating Systems Microsoft Windows Vista 32-bit, 64-bit Microsoft Windows XP Home Edition, Professional Microsoft Windows XP Tablet PC Edition 2005 Refer to marketing materials to find out what computer models support which Operating Systems. Version 4.1.3.1038 -------------------------------------------------------------------------------- WHAT THIS PACKAGE DOES This package provides the update utility of the following Intel Active Management Technology (AMT) software. - Management Engine Firmware Refer to marketing materials to find out what computer models support the AMT. Updating the software will fix problems, add new functions, or expand functions as noted below. -------------------------------------------------------------------------------- CHANGES IN THIS RELEASE Version 4.1.3.1038 Intel(R) AMT 4.1.3 Build Number 1038 [Important updates] - Some of ThinkPad models that have the following BIOS IDs can not use this Intel Management Engine Firmware. Models BIOS IDs ------------- -------- ThinkPad R400 7VETxxWW ThinkPad T400 7VETxxWW ThinkPad T500 7VETxxWW ThinkPad W500 7VETxxWW ThinkPad X200 7XETxxWW In order to determine the BIOS ID, refer to the "Determining which BIOS ID is installed" section. - Fixed security vulnerability issues that: 1. A vulnerability in which a malicious user with local machine access who had intimate Management Engine (ME)-knowledge could potentially exploit boundary errors in some ME application functions to gain control over those ME applications. 2. A remote Denial of Service (DOS) vulnerability which a malicious user could potentially exploit to cause the reboot of a system running susceptible versions of Intel Active Management Technology (AMT). [New functions or enhancements] - Added support for ThinkPad T400s. - Added support for some special characters in AMT host names, _ (underscore) and # (pound sign). (The first character must be an alpha character) - Added support for Intel WiFi/WiMax Link 5150. [Problem fixes] - Fixed an issue where Management Engine failed on remote power on. - Fixed an issue where Assert stolen command would fail if platform was halted (Intel AT-p). - Fixed an issue where AMT did not move to passive DHCP mode when closing network interface. This would lead to issues with provisioning from remote console. - Fixed an issue that had loss of AMT connectivity when connected to 1x network with no Operating System. - Fixed an issue that might cause unexpected shutdown or restart during resuming normal operation from standby state when Power Package PP2 (S0 + S3/AC), PP3 (S0 + S3,4,5/AC), PP4 (S0 + ME WoL in S3/AC), or PP5 (S0 + ME WoL in S3,4,5/AC) was used. -------------------------------------------------------------------------------- NOTES - Some of ThinkPad models that have the following BIOS IDs can not use this Intel Management Engine Firmware. Models BIOS IDs ------------- -------- ThinkPad R400 7VETxxWW ThinkPad T400 7VETxxWW ThinkPad T500 7VETxxWW ThinkPad W500 7VETxxWW ThinkPad X200 7XETxxWW In order to determine the BIOS ID, refer to the "Determining which BIOS ID is installed" section. -------------------------------------------------------------------------------- DETERMINING WHICH VERSION IS INSTALLED 1. Start Windows Vista, XP and logon with administrative privileges. 2. Open Command Prompt. 3. Move to the folder you extracted this package. 4. Type MEInfoWin.exe and press Enter. The following information will be displayed. Example: Copyright(C) 2005-08 Intel Corporation. All Rights Reserved. AMT SKU Found. Intel(R) MEInfo Win Version: 4.1.0.1023 BIOS Version: xxETxxWW (2.xx ) Intel(R) AMT code versions: Flash: 4.1.3 Netstack: 4.1.3 Apps: 4.1.3 Intel(R) AMT: 4.1.3 <--- SKU: ASF IAMT ITPM Tdt VendorID: 8086 Build Number: 1038 <--- 5. Note "Intel(R) AMT" and "Build Number", and refer to the Version Information section to check the installed version. If you see any errors, check Device Manager to see if the following device drivers are installed on the system: System devices Intel(R) Management Engine Interface If not installed, install using the following packages: Intel AMT 4.0 - Management Engine Interface -------------------------------------------------------------------------------- DETERMINING WHICH BIOS ID IS INSTALLED Use one of the following methods to check the BIOS ID. System Information in Windows: 1. Select Start, and All Programs, and Accessories, and System Tools, and then System Information. 2. Locate BIOS Version/Date line. 3. Check the BIOS ID (8-digit alphameric characters with the last two digits - WW) 4. If it is 7VETxxWW or 7XETxxWW, use the following Intel Management Engine Firmware at the following URL: http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-71806 BIOS Setup Utility: 1. Turn off the computer. 2. Turn on the computer. 3. While the "To interrupt normal startup, press the blue ThinkVantage button" message is displayed at the lower-left area of the screen, press the F1 key. The BIOS Setup Utility menu will be displayed. If a password prompt appears, type the correct password. 4. The BIOS ID is shown at the following line. BIOS Version BIOS version (BIOS ID) 5. Turn off the computer. 6. If it is 7VETxxWW or 7XETxxWW, use the following Intel Management Engine Firmware at the following URL: http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-71806 -------------------------------------------------------------------------------- UPDATE INSTRUCTIONS Notes: - If your computer runs satisfactorily now, it may not be necessary to update the software. To determine if you should update the software, refer to the Version Information section. - You may need to confirm with your IT administrator if you need to update Management Engine Firmware. - When you are updating Management Engine Firmware, make sure to connect an AC power and fully charged battery pack to your system. - You cannot down grade Management Engine Firmware version to any older version. - To use Intel Anti-Theft Technology PC Protection (AT-p), the BIOS that supports AT-p is required. Manual Update 1. Start Windows Vista, XP and logon with administrative privileges. 2. Open a Command Prompt. 3. Move to the folder you extracted this package. 4. Type MEUPDATE.CMD and press Enter. 5. Read the notice on the display, and press Enter. 6. Wait for about 3 minute until the message "Update finished successfully" is displayed. 7. Shut down the system. If the following error message is displayed, go to the "Update steps via TPM". Error <8721>: Firmware update through TPM is enabled. Use -tpm switch Update steps via TPM 1. Start Windows Vista, XP and logon with administrative privileges. 2. Open a Command Prompt. 3. Move to the folder you extracted this package. 4. There are two cases to update ME firmware: (A) If TPM is Unowned, type MEUPD.CMD and press Enter. (B) If TPM is Owned, type MEUPD_PW.CMD XXXXXXX and press Enter. where XXXXXXX is passphrase. Example: If passphrase is tpmpass123, MEUPD_PW.CMD tpmpass123 5. Read the notice on the display, and press Enter. 6. Wait about 12 minutes (on Windows Vista) or about 4 minutes (on Windows XP) until the message "Update finished successfully" is displayed. 7. Shut down the system. -------------------------------------------------------------------------------- VERSION INFORMATION The following versions have been released to date. Package version Intel AMT / Build Number Rev. Issue Date --------------- ------------------------ ---- --------------- 4.1.3.1038 4.1.3 / 1038 04 2009/06/11 4.1.3.1038 4.1.3 / 1038 03 2009/04/01 4.1.3.1038 4.1.3 / 1038 02 2009/02/12 4.1.3.1038 4.1.3 / 1038 01 2009/02/06 4.1.2.1030 4.1.2 / 1030 Initial Release Note: Revision number (Rev.) is for administrative purpose of this README document and is not related to software version. There is no need to upgrade this software when the revision number changes. To check the version of software, refer to the Determining which version is installed section. Summary of Changes Where: < > Package version number [Important] Important update (New) New function or enhancement (Fix) Correction to existing function <4.1.3.1038> - (New) Added support for ThinkPad T400s. <4.1.3.1038> - [Important] Some of ThinkPad models that have the following BIOS IDs can not use this Intel Management Engine Firmware. Models BIOS IDs ------------- -------- ThinkPad R400 7VETxxWW ThinkPad T400 7VETxxWW ThinkPad T500 7VETxxWW ThinkPad W500 7VETxxWW ThinkPad X200 7XETxxWW In order to determine the BIOS ID, refer to the "Determining which BIOS ID is installed" section. <4.1.3.1038> - [Important] Fixed security vulnerability issues that: 1. A vulnerability in which a malicious user with local machine access who had intimate Management Engine (ME)-knowledge could potentially exploit boundary errors in some ME application functions to gain control over those ME applications. 2. A remote Denial of Service (DOS) vulnerability which a malicious user could potentially exploit to cause the reboot of a system running susceptible versions of Intel Active Management Technology (AMT). - (Fix) Fixed an issue where Management Engine failed on remote power on. - (Fix) Fixed an issue where Assert stolen command would fail if platform was halted (Intel AT-p). - (Fix) Fixed an issue where AMT did not move to passive DHCP mode when closing network interface. This would lead to issues with provisioning from remote console. - (Fix) Fixed an issue that had loss of AMT connectivity when connected to 1x network with no Operating System. - (Fix) Fixed an issue that might cause unexpected shutdown or restart during resuming normal operation from standby state when Power Package PP2 (S0 + S3/AC), PP3 (S0 + S3,4,5/AC), PP4 (S0 + ME WoL in S3/AC), or PP5 (S0 + ME WoL in S3,4,5/AC) was used. <4.1.3.1038> - (New) Added support for some special characters in AMT host names, _ (underscore) and # (pound sign). (The first character must be an alpha character) - (New) Added support for Intel WiFi/WiMax Link 5150. <4.1.2.1030> - (New) (Initial release) Support for Intel Anti-Theft Technology PC Protection (AT-p) for ThinkPad T400. -------------------------------------------------------------------------------- TRADEMARKS * Lenovo and ThinkPad are registered trademarks of Lenovo. * Intel is a registered trademark of Intel Corporation. * Microsoft and Windows are registered trademarks of Microsoft Corporation. * Windows Vista is a trademark of Microsoft Corporation. Other company, product, and service names may be registered trademarks, trademarks or service marks of others.