Revision : 01 -------------------------------------------------------------------------------- Software name Intel Management Engine 11.8 Firmware Support models ThinkPad T480s(Machine types:20L7,20L8) ThinkPad X1 Carbon Gen 6 (Machine types:20KH,20KG) ThinkPad T480(Machine types:20L5,20L6) Operating System Microsoft Windows 10 64-bit Refer to marketing materials to find out what computer models support which Operating Systems. Version 11.8.77.3664 -------------------------------------------------------------------------------- WHAT THIS PACKAGE DOES This package updates the following software. - Intel Management Engine Firmware Refer to marketing materials to find out what computer models support Intel Management Engine. Updating the software will fix problems, add new functions, or expand functions as noted below. This program is language dependent, but can be used with any language system. -------------------------------------------------------------------------------- CHANGES IN THIS RELEASE Version 11.8.77.3664 [Important updates] Nothing. [New functions or enhancements] Nothing. [Problem fixes] -Fixed the following security vulnerabilities: CVE-20200531, CVE-20200532,CVE-20200533,CVE-20200535,CVE-20200536,CVE-20200537,CVE-20200538,CVE-20200539, CVE-20200540,CVE-20200545,CVE-20200594,CVE-20200595,CVE-20200596 and CVE-20208674. -Fixed an issue BSOD is observed when device guard is enabled. -Fixed an issue BSOD is observed when running WinPVT msc+Restart test. -Fixed an issue the system cannot establish TLS provision via Intel SCS ACU Wizard tool and a yellow bang is shown on Intel? MEI Driver. -Fixed an issue Failure in tests Intel? MEManufEOL var-f vPro_config.xml and MEDisable_Config.xml. -------------------------------------------------------------------------------- DETERMINING WHICH VERSION IS INSTALLED 1. Open the Command Prompt as administrator. [Mouse and Keyboard] 1. Hold down the Windows logo key and press X to open a menu at the lower -left area of the screen. 2. Select Command Prompt (Admin) from the menu, and select Yes. [Touch] 1. Press and hold the Start Button in the lower-left corner of the screen to open a menu. 2. Select Command Prompt (Admin) from the menu, and select Yes. 2. In the Command Prompt, type the following command and press Enter. [Path where the files were extracted]\MEInfoWin.exe Example: C:\DRIVERS\WIN\ME\MEInfoWin.exe The following information will be displayed. Example: Intel(R) MEInfo Version: 11.x.xx.xxxx Copyright(C) 2005 - 201x, Intel Corporation. All rights reserved. Intel(R) Manageability and Security Application code versions: BIOS Version: N2xETxxW (x.xx ) MEBx Version: 11.0.x.xxxx Gbe Version: x.x VendorID: 8086 PCH Version: x ==> FW Version: 11.8.77.3664 LP <== LMS Version: xxxx.xx.x.xxxx MEI Driver Version: xxxx.xx.x.xxxx 3. Check the FW Version. If you see any errors, check the Device Manager to see if the following device exists and is working properly. Under System devices category, Intel(R) Management Engine Interface If it does not exist, install the following software: Intel Management Engine 12.0 Software -------------------------------------------------------------------------------- NOTES Nothing. -------------------------------------------------------------------------------- UPDATE INSTRUCTIONS Important: - Before updating to this firmware, if you are using Intel Active Management Technology, Intel Small Business Technology, or Intel Standard Manageability, you should first unprovision your system by downloading and following the instructions available on the link below: https://downloadcenter.intel.com/search?keyword=unprovisioning%20tool *If these technologies are not configured on your system, you can disregard above information. *After unprovision and MEFW update, you can then re-provision your system. Note: - If your computer runs satisfactorily now, it may not be necessary to update the software. To determine if you should update the software, refer to the Version Information section. - Confirm first with your IT administrator if updating the Management Engine firmware is necessary. - Prior to the firmware update, connect the AC adapter and fully charged battery (if applicable) to the system. - Downgrading the Management Engine firmware to an older version cannot be allowed. - Make sure the following device is installed in the Device Manager. In the System devices category, Intel(R) Management Engine Interface If not exists, install the following software: Intel Management Engine 12.0 Software Manual Update This section assumes to use Microsoft Edge and Windows Explorer. Downloading files 1. Click once on the underlined file name. Once this is done, some pop-up windows will appear. 2. Follow the instructions on the screen. 3. In the window to choose "Save" or "Save as", click "Save". Once the download has completed, there may or may not be a message stating that the download completed successfully. Extracting files 4. Make sure to be logged on with an administrator account on the target computer. 5. Make sure the AC adapter is firmly connected to the target computer. 6. Open a Windows Explorer and select "Downloads" from "Quick access". 7. Locate the file that was downloaded and double-click it. 8. Follow the instructions on the screen. 9. In Extract or Install? window, select "Install", click Next, and move to step 13 to continue installation. Or, select "Extract only" and click Next to extract and keep the files on the specified folder. *Make sure there are no spaces on the directory path to where the ME Firmware Update package is to be extracted. 10. In the Select Destination Location window, click Extract. If you would like to select a different folder, click Browse. 11. All the necessary files will be extracted to the folder selected in the step 10. 12. Click Finish. Updating the ME Firmware 13. In the Ready to Install window, click Install. All the necessary files will be extracted to a temporary folder. And extracted files will be deleted after installation. 14. Click Finish. 15. In the Intel Management Engine FW Update Utility window, click Next to proceed. 16. Read all the requirements and warnings, then click Next. 17. When the message "Do you want to continue?" is displayed, click Yes to proceed with the ME firmware update. 18. When completed, a system reboot will be initiated to complete the firmware update. Unattended Install This is for system administrator's use only. 1. Refer to the Manual Install section, and download and extract the file. 2. Open Command Line with Administrator rights. 3. Navigate to the path where the files were extracted on Step 10 of "Extracting files" section and execute MEUpdate.CMD. Example: [Path where the files were extracted]\MEUpdate.CMD -------------------------------------------------------------------------------- VERSION INFORMATION The following versions have been released to date. Version Build ID Rev. Issue Date ------------ --------- ---- ---------- 11.8.77.3664 N23RG13W 01 2020/04/30 11.8.70.3626 N23RG12W 01 2019/09/17 11.8.65.3590 N23RG11W 01 2018/04/25 11.8.60.3561 N23RG10W 01 2018/12/12 11.8.55.3510 N23RG09W 01 2018/07/25 11.8.50.3460 N23RG08W 01 2018/03/30 11.8.50.3425 N23RG07W 01 2017/12/19 Note: Revision number (Rev.) is for administrative purpose of this README document and is not related to software version. There is no need to upgrade this software when the revision number changes. To check the version of software, refer to the Determining which version is installed section. Summary of Changes Where: < > Version number ( ) Build ID for administrative purpose [Important] Important update (New) New function or enhancement (Fix) Correction to existing function <11.8.77.3664>(N23RG13W) -(Fix) Fixed the following security vulnerabilities: CVE-20200531, CVE-20200532,CVE-20200533,CVE-20200535,CVE-20200536,CVE-20200537,CVE-20200538,CVE-20200539, CVE-20200540,CVE-20200545,CVE-20200594,CVE-20200595,CVE-20200596 and CVE-20208674. -(Fix) Fixed an issue BSOD is observed when device guard is enabled. -(Fix) Fixed an issue BSOD is observed when running WinPVT msc+Restart test. -(Fix) Fixed an issue the system cannot establish TLS provision via Intel SCS ACU Wizard tool and a yellow bang is shown on Intel? MEI Driver. -(Fix) Fixed an issue Failure in tests Intel? MEManufEOL var-f vPro_config.xml and MEDisable_Config.xml. <11.8.70.3626> (N23RG12W) -(Fix) Fixed the following security vulnerabilities: CVE-2019-0168, CVE-2019-0169, CVE-2019-11087, CVE-2019-11090, CVE-2019-11101, CVE-2019-11104 , CVE-2019-11106 , CVE-2019-11110, CVE-2019-11131 and CVE-2019-11132 -(Fix) Fixed an issue wherein the displayed copyright year in Intel AMT WebUI was 2005-2018 instead of 2005-2019 -(Fix) Fixed an issue wherein user was unable to log-in to Intel AMT WebUI over Chrome* browser -(Fix) Fixed an issue where BSOD was observed while entering/resuming Sleep/Hibernate. <11.8.65.3590> (N23RG11W) -(Fix) Fixed the following security vulnerabilities: CVE-2019-0090, CVE-2019-0092,CVE-2019-0093, CVE-2019-0094 and CVE-2019-0096. -(Fix) Fixed an issue where Mouse and Keyboard fail to wake up the screen when a KVM session is opened. -(Fix) Fixed an issue where there is an Incorrect Intel ME ICC settings after system resume from S3 or S4 states. -(Fix) Fixed an issue where Intel ME might fail to work properly after performing FW update. <11.8.60.3561> (N23RG10W) -(Fix) Fixed the following security vulnerabilities: CVE-2018-12188, CVE-2018-12189, CVE-2018-12190, CVE-2018-12191, CVE-2018-12192, CVE-2018-12199, CVE-2018-12187, CVE-2018-12196 and CVE-2018-12185. -(Fix) Fixed an issue where Intel(R) ME does not work properly after performing FW Update. -(Fix) Fixed an issue where firmware reset occurs when loading web storage when using MeshCommander. -(Fix) Fixed an issue where wrong Intel(R) LMS version is displayed when executing MeInfoWin64. -(Fix) Fixed an issue when starting user consent flow, MEBX Consent is not displayed. -(Fix) Fixed an issue when the platform is on S3 resume flow, the HECI SW fails to communicate with HECI FW. <11.8.55.3510>(N23RG09W) -(Fix) Fixed the following security vulnerabilities: CVE-2018-3655, CVE-2018-3657, CVE-2018-3658, CVE-2018-3659, CVE-2018-3616, CVE-2018-3643 and CVE-2018-3644. -(Fix) Fixed an issue where Intel(R) AMT might might fail to connecte to 802.1x WLAN Environment. -(Fix) Fixed an issue where Intel(R) FWUpdate tool might hang when attempting to perform an update on a corrupted image. -(Fix) Fixed an issue where Intel(R) MEInfo might return an error after running MEInfoWin64.exe. <11.8.50.3460>(N23RG08W) - (Fix) Mitigated security vulnerability CVE-2018-3628 (http://www.cve.mitre.org/cgibin/cvename.cgi?name=2018-3628 ) Details anticipated to be published June 11th 2018 - (Fix) Mitigated security vulnerability CVE-2018-3629 (http://www.cve.mitre.org/cgibin/cvename.cgi?name=2018-3629 ) Details anticipated to be published June 11th 2018 - (Fix) Mitigated security vulnerability CVE-2018-3627 (http://www.cve.mitre.org/cgibin/cvename.cgi?name=2018-3627 ) Details anticipated to be published June 11th 2018 - (Fix) The Power On Password(POP) /Hard Drive Password (HDP) is not automatically accepted and the user is prompted to enter the password again at reboot. This issue is seen only when performing the following PM flow directly after setting the POP/HDP in BIOS: S5/S4-> S0-> S3-> S0. - (Fix) CM3 flow during closemnf may cause a mismatch between NVAR to FPF fuses. - (Fix) After configuring SMLink1 to "NO" in IntelR FIT, GPP_C6 and GPP_C7 pins will be owned by IntelR ME instead of the Host after performing Moff-to-M3 or M3PG-to-M3 flow. - (Fix) The Platform with KBP-S randomly restarts itself in OS. - (Fix) Failure to install SW for Windows*10 RVP7 consumer production platforms. - (Fix) The platform hangs on POST screen after performing Clear CMOS showing "Unconfigure Without Password" "Get Uncofig Status Error" and "Unconfigure Without Password Error" messages. - (Fix) Resuming to OS takes a long time,(~35sec) when performing BIOS capsule update. - (Fix) The autocomplete HTML attribute is not disabled for password fields. - (Fix) Failure to run DASH* 2.0 tool on profile DMTF_Power_State_Management_1.0.2 - (Fix) IntelR ME SW installation process is incomplete in case the user does not click the "Finish" button but closes the installation window by clicking the [X] icon. - (Fix) The MUP.xml file for IntelR ME SW installer contains dummy data. - (Fix) IntelR SOL driver is non declarative and does not comply to DCHU requirements. - (Fix) IntelR MEInfo does not show some string values of FWSTS. - (Fix) IntelR MEInfo FWSTS could return irrelevant results. <11.8.50.3425>(N23RG07W) - (New) Initial release for ThinkPad T480s(Machine types:20L7,20L8)(Kolar-1), ThinkPad X1 Carbon (WW)(Machine types:20KH,20KG)(Yoda-2), ThinkPad X1 Carbon 6th (PRC)(Machine types:20KH,20KG)(Yoda-2), ThinkPad T480(Machine types:20L5,20L6)(Windu-2). -------------------------------------------------------------------------------- LIMITATIONS - Silent installation is not supported. -------------------------------------------------------------------------------- TRADEMARKS * Lenovo and ThinkPad are registered trademarks of Lenovo. * Intel is a registered trademark of Intel Corporation. * Microsoft, Internet Explorer and Windows are registered trademarks of Microsoft Corporation. Other company, product, and service names may be registered trademarks, trademarks or service marks of others.