<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenSSL vulnerability in icls driver version 1.71.99.0 in Mobile and Desktop Processors</title>
    <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620101#M75491</link>
    <description>&lt;P&gt;If you need the full set of Windows drivers for both Windows 10 as well as 11 the MS catalog link is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.catalog.update.microsoft.com/Search.aspx?q=Intel+-+SoftwareComponent+-+1+72" target="_blank"&gt;https://www.catalog.update.microsoft.com/Search.aspx?q=Intel+-+SoftwareComponent+-+1+72&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2024 23:36:17 GMT</pubDate>
    <dc:creator>KerrAvon</dc:creator>
    <dc:date>2024-08-01T23:36:17Z</dc:date>
    <item>
      <title>OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1597144#M72354</link>
      <description>&lt;P&gt;According to Microsoft Defender, the icls driver installed on 80% of our devices uses OpenSSL version 3.0.12. This version has known vulnerabilities.&lt;/P&gt;&lt;P&gt;The driverversion is 1.71.99.0 which is the latest from Windows Update and also the lastest I can find on the Intel-site (&lt;A href="https://www.intel.com/content/www/us/en/download/682431/intel-management-engine-drivers-for-windows-10-and-windows-11.html?wapkw=intel%20r%20icss%20client" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/682431/intel-management-engine-drivers-for-windows-10-and-windows-11.html?wapkw=intel%20r%20icss%20client&lt;/A&gt;).&lt;BR /&gt;&lt;BR /&gt;Is there&amp;nbsp; a newer version which I missed? If not, when can we expect an updated driverpackage?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 05:53:04 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1597144#M72354</guid>
      <dc:creator>MaximvL</dc:creator>
      <dc:date>2024-05-13T05:53:04Z</dc:date>
    </item>
    <item>
      <title>Re:OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1599759#M72644</link>
      <description>&lt;P&gt;Hello MaximvL,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for posting in our communities.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I will raise the case with our engineers so they can provide us with the correct information.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I'll post the response to this thread here once it is available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your patience and understanding!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Carmona A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 22 May 2024 11:21:34 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1599759#M72644</guid>
      <dc:creator>ACarmona_Intel</dc:creator>
      <dc:date>2024-05-22T11:21:34Z</dc:date>
    </item>
    <item>
      <title>Re:OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1601866#M72879</link>
      <description>&lt;P&gt;Hello MaximvL,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for patiently waiting on our response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In order to delve deeper into this issue, we would like to ask about the specific make and model of your system, as well as your processor model. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Additionally, if you wish to report any security vulnerabilities related to Intel® products, we encourage you to check out our article titled&lt;A href="https://www.intel.com/content/www/us/en/support/articles/000056781/programs/intel-corporation.html" rel="noopener noreferrer" target="_blank"&gt;&amp;nbsp;'How Do I Report Security and Vulnerability Issues Related to Intel® Products?'&lt;/A&gt;&amp;nbsp;for detailed guidance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We look forward to your response!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Carmona A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 May 2024 07:40:39 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1601866#M72879</guid>
      <dc:creator>ACarmona_Intel</dc:creator>
      <dc:date>2024-05-29T07:40:39Z</dc:date>
    </item>
    <item>
      <title>Re:OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1603289#M73036</link>
      <description>&lt;P&gt;Hello MaximvL,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We are checking in with you to see if you already have the answers to our questions so we can further isolate our issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you, and have a great day!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Carmona A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jun 2024 10:26:34 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1603289#M73036</guid>
      <dc:creator>ACarmona_Intel</dc:creator>
      <dc:date>2024-06-03T10:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1603306#M73040</link>
      <description>&lt;P&gt;Carmona,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have dozens of models with this issue. p.e. Dell Latitude 5540 13th Gen Intel(R) Core(TM) i5-1335U&lt;/P&gt;&lt;P&gt;I will send a mail as detailed in the link you send.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 11:49:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1603306#M73040</guid>
      <dc:creator>MaximvL</dc:creator>
      <dc:date>2024-06-03T11:49:24Z</dc:date>
    </item>
    <item>
      <title>Re:OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1603483#M73056</link>
      <description>&lt;P&gt;Hello MaximvL,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for providing us with the details that we have requested. It is highly noted.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Yes, please do send an email using the link that we have provided so the right team can provide you with appropriate assistance regarding the security and vulnerability related to our Intel products.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;By the way, I will now raise the case again with our engineers so they can thoroughly investigate the issue and provide us with a recommendation.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I will get back to you as soon as I have our engineers response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Again, thank you so much for your patience.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Carmona A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Jun 2024 01:48:33 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1603483#M73056</guid>
      <dc:creator>ACarmona_Intel</dc:creator>
      <dc:date>2024-06-04T01:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1604171#M73112</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;Same issue here with several hundred Microsoft Surface Laptop and Surface Pro devices.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Specifically, the vulnerability is with the below files under folder c:\windows\system32\driverstore\filerepository\ that are part of the Intel ICLS driver packages installed on these devices:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;libssl-1_1-x64.dll&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;libcrypto-1_1-x64.dll&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;libssl-3-x64.dll&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;libcrypto-3-x64.dll&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Many devices have two versions of the Intel ICLS drivers within&amp;nbsp;c:\windows\system32\driverstore\filerepository\ - one version with OpenSSL 1.1.1.0 DLLs and another with version OpenSSL 3.0.11.0 DLLs.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Installing the current Intel ME driver package using the installer linked in original post does not uninstall the old versions. There is also no entry in Add/Remove Programs to uninstall the older versions of ICLS.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;What is the recommended method for removing old versions of Intel ICLS drivers from multiple devices?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 18:57:27 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1604171#M73112</guid>
      <dc:creator>Account2241</dc:creator>
      <dc:date>2024-06-05T18:57:27Z</dc:date>
    </item>
    <item>
      <title>Re:OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1604430#M73145</link>
      <description>&lt;P&gt;Hello MaximvL,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for patiently waiting on our response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please continue to contact the &lt;A href="https://www.intel.com/content/www/us/en/support/articles/000056781/programs/intel-corporation.html" rel="noopener noreferrer" target="_blank"&gt;Intel Product Security Incident Response Team&lt;/A&gt; for your concern; they will provide you with the appropriate recommendation that you need.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;You may use this thread as a reference once you have contacted them.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.intel.com/t5/Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1597144#M72354" rel="noopener noreferrer" target="_blank"&gt;MaximvL Community thread&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;By the way, we will now be closing this case. For additional information, please submit a new question, as this thread will no longer be monitored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Carmona A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Jun 2024 08:57:43 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1604430#M73145</guid>
      <dc:creator>ACarmona_Intel</dc:creator>
      <dc:date>2024-06-06T08:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1610453#M73867</link>
      <description>&lt;P&gt;Is there any follow up on this?&amp;nbsp; As the OP reported, the current versions of the ICLS client uses OpenSSL 3.0.12.0 and like OpenSSL 3.0.11.0, that is also vulnerable.&lt;/P&gt;&lt;P&gt;How soon will you have your OpenSSL drivers updated to an available-for-download version that is &lt;STRONG&gt;not&lt;/STRONG&gt; vulnerable?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 21:40:48 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1610453#M73867</guid>
      <dc:creator>RobynAnn</dc:creator>
      <dc:date>2024-06-27T21:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1616890#M74762</link>
      <description>&lt;P&gt;I'm also facing this issue due to ICLS client in the drivers folder path, where ICLS client uses OpenSSL 3.0.12.0, which is vulnerable.&lt;BR /&gt;&lt;BR /&gt;Can you please share an ETA, or steps how we can update it, as it not getting updated with the windows updates for drivers.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 06:28:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1616890#M74762</guid>
      <dc:creator>DeepakSingh</dc:creator>
      <dc:date>2024-07-22T06:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Re:OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1617303#M74841</link>
      <description>&lt;P&gt;Having the same issue with the Intel Management Engine on Dell PCs&lt;/P&gt;&lt;P&gt;Ran the Dell command update which did update some of the component files with new versions however the libssl/libcrypto libraries are still showing as 3.0.11.0&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is causing an adverse vulnerability score in Microsoft Defender which indicates that upgrading to 3.3.0.0 is required.&lt;/P&gt;&lt;P&gt;My client is very security focussed &amp;amp; we have to submit a monthly report. Questions are being asked why a global organization like Intel are packaging versions that have been superseded multiple times.&lt;/P&gt;&lt;P&gt;A prompt resolution to this issue is requested&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 07:19:09 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1617303#M74841</guid>
      <dc:creator>KerrAvon</dc:creator>
      <dc:date>2024-07-23T07:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1618304#M75061</link>
      <description>&lt;P&gt;We have the same problem. Is ther a solution for ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 07:38:03 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1618304#M75061</guid>
      <dc:creator>TItus2</dc:creator>
      <dc:date>2024-07-26T07:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1619901#M75425</link>
      <description>&lt;P&gt;Have the same problem with various Dell desktop and laptop devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ending up Defender flagging it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting wrinkle we have is that one 'instance' of ICLS' shows up in C:\Windows\system32\driverstore\filerepository\iclsclient.*&lt;/P&gt;&lt;P&gt;and another instance shows up on the same machine in c:\Windows\Temp\ii*.tmp\icls_dch\*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will be the same version of OpenSSL in the two locations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing shows up in the Windows Installed Apps list for ICLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the Dell site, it kind of reads that the Dell Management Engine Components Installer kit contains the ICLS client software. This evening, that kit is listed as a critical install and &lt;STRONG&gt;does&lt;/STRONG&gt; show up on our devices as being installed as version 2345.5.42.0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=7fhff&amp;amp;oscode=w2021&amp;amp;productcode=optiplex-3070-sff" target="_blank"&gt;https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=7fhff&amp;amp;oscode=w2021&amp;amp;productcode=optiplex-3070-sff&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you go through the Dell Security Update message to see all the CVE's that the above kit takes care of, none of them match the 6 CVE's that Defender lists out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dell.com/support/kbdoc/en-us/000217983/dsa-2023-364-security-update-for-dell-client-bios-for-intel-platform-update-2024-1-advisories" target="_blank"&gt;https://www.dell.com/support/kbdoc/en-us/000217983/dsa-2023-364-security-update-for-dell-client-bios-for-intel-platform-update-2024-1-advisories&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure seems like there are serious disconnects between CVE numbers, what files are where, what larger update kits have other embedded kits within them and if so what versions of the smaller kits are included.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All to get to the point of knowing what kit the bundles up the right subkits all to get off the complaint list of Defender.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm starting to think this is a never ending, very ugly task with a lot of disappointments along the way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll go back to my bleacher seat now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pdc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 04:09:06 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1619901#M75425</guid>
      <dc:creator>pdc99</dc:creator>
      <dc:date>2024-08-01T04:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1619936#M75435</link>
      <description>&lt;P&gt;I got a respons from Intel:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for your patience during our investigation, Intel recommends you upgrade your affected systems to ICLS Client Driver version 1.72.189.0 &amp;nbsp;that mitigates these CVEs.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;In future if you have a vulnerability scanner reporting a known third-party, open-source CVE in an Intel driver or other component. Keep in mind that Intel routinely scans for 3rd party vulnerabilities and updates these components. Please check the &lt;A href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.intel.com%2Fcontent%2Fwww%2Fus%2Fen%2Fdownload-center%2Fhome.html&amp;amp;data=05%7C02%7CMaxim.vanLuttikhuizen%40derolfgroep.nl%7C11da992ee9654898fe9508dcb173e6dd%7C735ff4300ae547b598023998db9ee0b2%7C0%7C0%7C638580358580205459%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;amp;sdata=FWeAXpv0GTr9YqMm93gs6knTfCgKqOXIGvlkZ1xw%2Bx4%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Intel Download Center&lt;/A&gt; for the latest version.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And indeed the 1.72.189.0 version has the new OpenSSL version&lt;/P&gt;&lt;P&gt;The CAB-file can be downloaded at Microsoft:&amp;nbsp;&lt;A href="https://www.catalog.update.microsoft.com/Search.aspx?q=intel%20icls%20windows%2011%20%201.72.189.0" target="_blank"&gt;https://www.catalog.update.microsoft.com/Search.aspx?q=intel%20icls%20windows%2011%20%201.72.189.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be Nice if Microsoft and/or the manufacturer of our laptops would make this update available through the regular updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 07:19:01 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1619936#M75435</guid>
      <dc:creator>MaximvL</dc:creator>
      <dc:date>2024-08-01T07:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620090#M75487</link>
      <description>&lt;P&gt;MaximvL..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recommend that you don't get your hopes up with that CAB file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It contains OpenSSL 3.0.13 files, which also get flagged by Defender as a security problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I poked around on one of the desktop devices we have and then did a bunch of reading and more poking around.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My test device has 2 icls* folders at c:\Windows\system32\driverstore\filerepository\*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One has OpenSSL 3.0.12 the other 3.0.13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ran the Intel CSME Version Detection Tool which said the device was okay with Version 10.0, which is the latest CSME version available.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/19392/intel-converged-security-and-management-engine-version-detection-tool-intel-csmevdt.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/19392/intel-converged-security-and-management-engine-version-detection-tool-intel-csmevdt.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CSME Version 10 was released on 4/8/24 based on above web page.&lt;/P&gt;&lt;P&gt;OpenSSL 3.0.12 was released on:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10/24/24&lt;/P&gt;&lt;P&gt;OpenSSL 3.0.13 was released on:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1/30/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since OpenSSL V3.0.13 was released there has been 13 updates, excluding alpha/beta releases, to OpenSSL with the latest being 3.3.1 on 6/4/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reading through the following article, it looks like the previous security update for Intel CSME and AMT was 8/11/22.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/support/articles/000031784/technologies.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/support/articles/000031784/technologies.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could very well be missing information, but it doesn’t look like CSME gets updated often. And there are questions remaining about any new CSME version doing uninstallations of previous versions of ‘sub-kits’ like OpenSSL to clean up a device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Heavy Sigh…&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 21:49:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620090#M75487</guid>
      <dc:creator>pdc99</dc:creator>
      <dc:date>2024-08-01T21:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620091#M75488</link>
      <description>&lt;P&gt;MaximvL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forgot to mention in my earlier posts that I have been chatting with the Intel SIRT as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their 1st reply was along the lines of what you posted which made little sense to me, so I replied back with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;I have read through your response several&amp;nbsp;times and admit that I do not understand what is being said here.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Regarding the 1st&amp;nbsp;paragraph, I go to the Intel download center and search for "ICLS Client Driver" and get 30 matches spread over 3 pages. On those pages, there are no entries saying 'ICLS Client Driver'. I then look for a version number of 1.72.189.0 among those 30 entries and none of them has that version number.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;A class="" title="Original URL: https://www.intel.com/content/www/us/en/search.html?ws=idsa-default#q=ICLS%20Client%20driver&amp;amp;first=20&amp;amp;sort=relevancy&amp;amp;f:@tabfilter=[Downloads]. Click or tap if you trust this link." href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.intel.com%2Fcontent%2Fwww%2Fus%2Fen%2Fsearch.html%3Fws%3Didsa-default%23q%3DICLS%2520Client%2520driver%26first%3D20%26sort%3Drelevancy%26f%3A%40tabfilter%3D%5BDownloads%5D&amp;amp;data=05%7C02%7Csrsterling%40pleasantvilleucc.org%7C99c2a9f12f4c436b67a808dcb1d966dc%7Ca0a59de33df0438799e418920807bef8%7C0%7C0%7C638580794502926173%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;amp;sdata=5xBz%2Bf6aC89Xx%2FbA%2FcXGe0%2Fhv9Wf4jGG0go1nlvpyAk%3D&amp;amp;reserved=0" target="_blank" rel="noopener noreferrer"&gt;https://www.intel.com/content/www/us/en/search.html?ws=idsa-default#q=ICLS%20Client%20driver&amp;amp;first=20&amp;amp;sort=relevancy&amp;amp;f:@tabfilter=[Downloads]&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I searched&amp;nbsp; for that specific version number, 1.72.189.0, and find no matches.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;A title="Original URL: https://www.intel.com/content/www/us/en/search.html?ws=idsa-default#q=%221.72.189.0%22&amp;amp;sort=relevancy&amp;amp;f:@tabfilter=[Downloads]. Click or tap if you trust this link." href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.intel.com%2Fcontent%2Fwww%2Fus%2Fen%2Fsearch.html%3Fws%3Didsa-default%23q%3D%25221.72.189.0%2522%26sort%3Drelevancy%26f%3A%40tabfilter%3D%5BDownloads%5D&amp;amp;data=05%7C02%7Csrsterling%40pleasantvilleucc.org%7C99c2a9f12f4c436b67a808dcb1d966dc%7Ca0a59de33df0438799e418920807bef8%7C0%7C0%7C638580794502940531%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;amp;sdata=L0rboQJgjHhv3tHCgObqhKk7LjGJHt1SqHVEYjIMT80%3D&amp;amp;reserved=0" target="_blank" rel="noopener noreferrer"&gt;https://www.intel.com/content/www/us/en/search.html?ws=idsa-default#q=%221.72.189.0%22&amp;amp;sort=relevancy&amp;amp;f:@tabfilter=[Downloads]&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;What part of a magic decoder ring am I missing to understand what you said and how to find what I am searching for in the future?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;------------------&lt;/DIV&gt;&lt;DIV class=""&gt;Today, Intel SIRT sent the following reply.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ICLS Client Driver is not a standalone product and hence you were not able to find it on the Intel download center, its part of Intel Converged Security and Management Engine (Intel CSME). By updating to the latest version of CSME the ICLS client driver will be automatically updated to the version listed below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Which lead me to do more poking around with that result being what I posted a few minutes ago.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 22:01:26 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620091#M75488</guid>
      <dc:creator>pdc99</dc:creator>
      <dc:date>2024-08-01T22:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620101#M75491</link>
      <description>&lt;P&gt;If you need the full set of Windows drivers for both Windows 10 as well as 11 the MS catalog link is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.catalog.update.microsoft.com/Search.aspx?q=Intel+-+SoftwareComponent+-+1+72" target="_blank"&gt;https://www.catalog.update.microsoft.com/Search.aspx?q=Intel+-+SoftwareComponent+-+1+72&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 23:36:17 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1620101#M75491</guid>
      <dc:creator>KerrAvon</dc:creator>
      <dc:date>2024-08-01T23:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1624137#M76436</link>
      <description>&lt;P&gt;PDC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last friday I got the following reply from Dell:&lt;BR /&gt;&lt;BR /&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;There will be a Dell certified version released as follows:&lt;/P&gt;&lt;P&gt;Intel ME FW - Ver. 16.1.32.2418 v0.2&lt;/P&gt;&lt;P&gt;Intel ME Driver - Ver. 2413.5.68.0 / with iCLS v1.72.189.0&lt;/P&gt;&lt;P&gt;Target release date – 2024/10/8.&lt;BR /&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So , I guess this will be october 8th and not august 10th as the sentence is in future tense and the Dell Driver downloads still show 2413.5.67.0.&lt;BR /&gt;Now, Windows also retains the second to last driver in the driver store so this update will patch the active drivers but Defender will keep flagging the older inactive driver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you stated, the driver files in Windows Temp are also flagged. I cleared these files using a script.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You won't find the software in Apps but you can find the active driver used in device managment --&amp;gt; Software Components --&amp;gt; Intel(R) iCLS Client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 10:10:36 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1624137#M76436</guid>
      <dc:creator>MaximvL</dc:creator>
      <dc:date>2024-08-19T10:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1637121#M78273</link>
      <description>&lt;P&gt;Has anyone been able to resolve this issue in Microsoft Defender? We are having the same issue with a client that requires CVE's to be resolved within 14 days. It's been many months!! I had a ticket open with Microsoft and they are telling me I need to contact Intel.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 15:38:28 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1637121#M78273</guid>
      <dc:creator>Jeff-Wampler</dc:creator>
      <dc:date>2024-10-14T15:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL vulnerability in icls driver version 1.71.99.0</title>
      <link>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1663739#M81409</link>
      <description>&lt;P&gt;8 months and still no reply from Intel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HELLO?!?!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AndAuf_0-1738845183763.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62604i4B32ACFC98E61F8E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="AndAuf_0-1738845183763.png" alt="AndAuf_0-1738845183763.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 12:35:28 GMT</pubDate>
      <guid>https://community.intel.com/t5/Mobile-and-Desktop-Processors/OpenSSL-vulnerability-in-icls-driver-version-1-71-99-0/m-p/1663739#M81409</guid>
      <dc:creator>AndAuf</dc:creator>
      <dc:date>2025-02-06T12:35:28Z</dc:date>
    </item>
  </channel>
</rss>

