Revision : 01 -------------------------------------------------------------------------------- Software name Intel Management Engine 8.1 Firmware Support models ThinkPad Helix ThinkPad T430, T430i, T430s, T430si, T431s ThinkPad T530, T530i ThinkPad W530 ThinkPad X1 Carbon (Machine types: 34xx), X1 Helix, X1 Helix 3G ThinkPad X230, X230i, X230 Tablet, X230i Tablet, X230s Operating Systems Microsoft Windows 10 64-bit Microsoft Windows 8.1 64-bit Microsoft Windows 8 64-bit Microsoft Windows 7 32-bit, 64-bit Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP3 Microsoft Windows XP Tablet PC Edition 2005 SP3 Refer to marketing materials to find out what computer models support which Operating Systems. Version 8.1.71.3608 -------------------------------------------------------------------------------- WHAT THIS PACKAGE DOES This package updates the following software. - Intel Management Engine Firmware Refer to marketing materials to find out what computer models support Intel Management Engine. Updating the software will fix problems, add new functions, or expand functions as noted below. This program is language dependent, but can be used with any language system. -------------------------------------------------------------------------------- CHANGES IN THIS RELEASE Version 8.1.71.3608 [Important updates] Nothing. [New functions or enhancements] Nothing. [Problem fixes] - Fixed CVE-2017-5689: Escalation of privilege vulnerability in Intel(R) Active Management Technology (AMT), Intel(R) Standard Manageability (ISM), and Intel(R) Small Business Technology. -------------------------------------------------------------------------------- DETERMINING WHICH VERSION IS INSTALLED 1. Open the Command Prompt as administrator. [Windows 8 or later] [Mouse and Keyboard] 1. Hold down the Windows logo key and press X to open a menu at the lower -left area of the screen. 2. Select Command Prompt (Admin) from the menu, and select Yes. [Touch] 1. From the Start screen, select Desktop. 2. Open a Windows Explorer and select the C drive. 3. Select File, and select Open command prompt > Open command prompt as administrator. [Windows 7] 1. Open the Start menu, type cmd in the search box and press Ctrl+Shift+Enter. [Windows XP] 1. Open the Start menu, select Run. 2. Type RUNAS /USER:administrator cmd.exe and press Enter. 3. Enter the Administrator password. 2. In the Command Prompt, type the following command and press Enter. [Path where the files were extracted]\MEInfoWin.exe Example: C:\DRIVERS\WIN\ME\MEInfoWin.exe The following information will be displayed. Example: Intel(R) MEInfo Version: 8.1.56.1541 Copyright(C) 2005 - 2014, Intel Corporation. All rights reserved. Intel(R) Manageability and Security Application code versions: BIOS Version: G1ETA8WW (2.68 ) MEBx Version: 8.0.0.0069 Gbe Version: 1.3 VendorID: 8086 PCH Version: 4 FW Version: 8.1.71.3608 <== 3. Check the FW Version. If you see any errors, check the Device Manager to see if the following device exists and is working properly. Under System devices category, Intel(R) Management Engine Interface If it does not exist, install the following software: For Windows 10, 8.1, 8, 7: Intel Management Engine 11.0 Software For Windows XP: Intel Management Engine 9.0 Software -------------------------------------------------------------------------------- NOTES - Updating Management Engine firmware while Microsoft BitLocker drive encryption is enabled will cause subsequent boots of the encrypted drive to fail. If you are using BitLocker, refer to BitLocker help for information on how to temporarily disable BitLocker before updating your Management Engine firmware. -------------------------------------------------------------------------------- UPDATE INSTRUCTIONS Important: - Before updating to this firmware, if you are using Intel Active Management Technology, Intel Small Business Technology, or Intel Standard Manageability, you should first unprovision your system by downloading and following the instructions available on the link below: https://downloadcenter.intel.com/search?keyword=unprovisioning%20tool *If these technologies are not configured on your system, you can disregard above information. *After unprovision and MEFW update, you can then re-provision your system. Note: - If your computer runs satisfactorily now, it may not be necessary to update the software. To determine if you should update the software, refer to the Version Information section. - Confirm first with your IT administrator if updating the Management Engine firmware is necessary. - Prior to the firmware update, connect the AC adapter and fully charged battery (if applicable) to the system. - Downgrading the Management Engine firmware to an older version cannot be allowed. - Make sure the following device is installed in the Device Manager. In the System devices category, Intel(R) Management Engine Interface If it does not exist, install the following software: Intel Management Engine Interface 9.5 and Serial Over LAN (SOL) Driver Manual Update This section assumes to use Internet Explorer and Windows Explorer. Downloading file 1. Select the underlined file name. Once this is done, some pop-up windows will appear. 2. Follow the instructions on the screen. 3. When the selection message of the Run or Save on the window, select Save. 4. Once the download has completed, there may or may not be a message stating that the download completed successfully. Extracting file 5. Make sure to be logged on with an administrator account. 6. Locate the folder where the file was downloaded. 7. Locate the file that was downloaded and double-click/double-tap it. The file name ends with "WW.EXE" for Windows 7, 8 and XP 32-bit, "XP64.EXE" for Windows XP Professional x64 Edition. 8. Follow the instructions on the screen. 9. In the Select Destination Location window, select Next. If you would like to select a different folder, select Browse. 10. In the Ready to Install window, select Install. All the necessary files will be extracted to the folder selected in the step 9. Updating 11. Open a Command Prompt as administrator. [Windows 8 or later] [Mouse and Keyboard] 1. Hold down the Windows logo key and press X to open a menu at the lower -left area of the screen. 2. Select Command Prompt (Admin) from the menu, and select Yes. [Touch] 1. Press and hold the Start Button in the lower-left corner of the screen to open a menu. 2. Select Command Prompt (Admin) from the menu, and select Yes. [Windows 7] 1. Open the Start menu, type cmd in the search box and press Ctrl+Shift+Enter. [Windows XP] 1. Open the Start menu, select Run. 2. Type RUNAS /USER:administrator cmd.exe and press Enter. 3. Enter the Administrator password. 12. In the Command Prompt, type the following command and press Enter. [Path where the files were extracted]\MEUpdate.cmd Example: C:\DRIVERS\WIN\ME\MEUpdate.cmd 13. Read the warning on the display, and press Y or N. If you press Y, ME updating will progress. 14. Read the notifications on the display, type Y and press Enter to proceed. Wait for about 2 minutes until the message, Update finished successfully, is displayed. 15. Close the Command Prompt window, and then shut down the computer. Finally delete the file saved in the step 4. -------------------------------------------------------------------------------- VERSION INFORMATION The following versions have been released to date. Version Build ID Rev. Issue Date ------------- -------- ---- ---------- 8.1.71.3608 G1RG23WW 01 2017/05/18 8.1.70.1590 G1RG22WW 01 2016/01/22 8.1.60.1561 G1RG21WW 02 2015/06/19 8.1.60.1561 G1RG21WW 01 2014/12/26 8.1.57.1556 G1RG20WW 01 2014/10/13 8.1.55.1506 G1RG19WW 01 2014/05/19 8.1.52.1496 G1RG18WW 01 2014/02/21 8.1.51.1471 G1RG17WW 01 2013/11/01 8.1.40.1416 G1RG16WW 01 2013/07/01 8.1.30.1350 G1RG14WW 01 2013/03/15 8.1.20.1336 G1RG12WW 03 2013/01/18 8.1.20.1336 G1RG12WW 02 2012/11/30 8.1.20.1336 G1RG12WW 01 2012/11/20 8.1.2.1318 G1RG10WW 02 2012/11/01 8.1.2.1318 G1RG09WW 01 2012/10/19 8.1.0.1265 G1RG07WW 01 2012/09/24 Note: Revision number (Rev.) is for administrative purpose of this README document and is not related to software version. There is no need to upgrade this software when the revision number changes. To check the version of software, refer to the Determining which version is installed section. Summary of Changes Where: < > Version number ( ) Build ID for administrative purpose [Important] Important update (New) New function or enhancement (Fix) Correction to existing function <8.1.71.3608> (G1RG23WW) - (Fix) Fixed CVE-2017-5689: Escalation of privilege vulnerability in Intel(R) Active Management Technology (AMT), Intel(R) Standard Manageability (ISM), and Intel(R) Small Business Technology. <8.1.70.1590> (G1RG22WW) - (New) Added SHA2 root certificate hashes to support Remote Configuration. - (New) For the same root certificates, replaced all existing default SHA1 hashes from SHA1 hash with SHA256 hashes - (Fix) Fixed an issue where Alarm Clock event might have wrong description when machine wakes from alarm. - (Fix) Fixed an issue where SOL/KVM/IDER 802.1x session might close prematurely after restart. <8.1.60.1561> (G1RG21WW) - (New) Added support for Microsoft Windows 10 <8.1.60.1561> (G1RG21WW) - [Important] Removed SSL 3.0 support from Intel ME firmware because SSL 3.0 was vulnerable to the Padding Oracle On Downgraded Legacy (POODLE) attack. <8.1.57.1556> (G1RG20WW) - (New) Added support for preventing ME and Host Wireless LAN from communicating when there was no request for Wireless LAN usage from ME applications. - (Fix) Fixed an issue that returned Audit Log records with an invalid Kerberos user. <8.1.55.1506> (G1RG19WW) - (New) Added support for HDCP 2.2 used by Intel WiDi. - (Fix) Fixed an issue where Intel ME LAN ARP replied Broadcast instead of Unicast. <8.1.52.1496> (G1RG18WW) - (Fix) Fixed an issue where provisioning with PKI failed when the DNS infrastructure was implemented with an FQDN that ended with a trailing dot. - (Fix) Specified the machine types of ThinkPad X1 Carbon (Machine types: 34xx). <8.1.51.1471> (G1RG17WW) - [Important] Added support for Microsoft Windows 8.1. <8.1.40.1416> (G1RG16WW) - (New) Added support for Continuous Aware Mode (CAM) during wireless redirection sessions. - (New) Updated HDCP for Intel WiDi to version 2.1. - (New) Decreased the link protection host connection and reconnection timers from 5 to 3 seconds. - (Fix) Fixed an security vulnerability issue. <8.1.30.1350> (G1RG14WW) - (New) Added support for ThinkPad T431s,X230s. - (Fix) Fixed Intel MEI uninstallation dialog box on Brazilian/Portuguese language OS systems. - (Fix) Enhanced security function of LMSService. <8.1.20.1336> (G1RG12WW) - (New) Added support for ThinkPad Helix,X1 Helix,X1 Helix 3G. <8.1.20.1336> (g1rg12ww) - (New) Added support for Microsoft Windows XP Professional x64 Edition. - (Fix) Fixed an issue where TLS session could not be established when using TLS 1.1 version. - (Fix) Fixed an issue where sending a WS-MAN command with special parameters would trigger a firmware exception. <8.1.20.1336> (G1RG12WW) - (Fix) Fixed an issue of ME update error on some system configurations. (Removed the Recovering From ME Update Error section from this document.) <8.1.2.1318> (G1RG10WW) - (New) Added the Recovering From ME Update Error section. <8.1.2.1318> (G1RG09WW) - (New) Added support for Microsoft Windows 7 and Windows XP. - (Fix) Fixed some issues. <8.1.0.1265> (G1RG07WW) - (New) Initial release for ThinkPad T430,T430i,T430s,T430si,T530,T530i,W530, X1 Carbon,X230,X230i,X230 Tablet,X230i Tablet. -------------------------------------------------------------------------------- LIMITATIONS Nothing. -------------------------------------------------------------------------------- TRADEMARKS * Lenovo and ThinkPad are registered trademarks of Lenovo. * Intel is a registered trademark of Intel Corporation. * Microsoft, BitLocker, Internet Explorer and Windows are registered trademarks of Microsoft Corporation. Other company, product, and service names may be registered trademarks, trademarks or service marks of others.