Processors
Intel® Processors, Tools, and Utilities
14507 Discussions

Vulnerability and Intel-SA-00075

MBrok1
Beginner
1,647 Views

Hello everybody, I hope someone could help me.

I have a PC (assembled with hardware I bought) with a i5-4460 processor, and after running Intel-SA-00075-gui.exe the next information is showed:

Based on the analysis performed by this tool, this system is vulnerable.

Manufacturer: Gigabyte Technology Co., Ltd.

Model: B85M-D3H

Processor Name: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz

Windows Version: Microsoft Windows 10 Home

Version: 9.0.30.1482

SKU: Intel(R) Small Business Advantage (SBA)

Provisioning Mode: Not Provisioned

Control Mode: None

Is CCM Disabled: False

Driver installation found: True

EHBC Enabled: False

LMS service state: Running

microLMS service state: NotPresent

I run the following command (although it appears to be disabled):

C:\...>INTEL-SA-00075-console.exe -Unprovision

Unprovision error: Intel(R) AMT is already unconfigured on this system.

The next command stops LMS:

C:\...>INTEL-SA-00075-console.exe -disableLMS

There is a -disableCCM option, but I haven't used it because maybe cannot be reverted.

But I already get the vulnerable system message.

As I don't have an OEM PC, which commands must I use with Intel-SA-00075-console.exe (safely) to solve the problem ?

Thanks !

0 Kudos
3 Replies
idata
Employee
602 Views

MikiBroki: Thank you very much for joining the Intel® Processors communities.

 

 

Based on the information provided above, you already ran the proper commands and it seems that everything is disable now.

 

However, you do have an OEM board that belongs to Gigabyte, and the board will still be vulnerable until Gigabyte releases a new BIOS version to fix this problem. So, the best thing to do will be to get in contact directly with them in order to get further details about this subject:

https://www.gigabyte.com/Support

Any further questions, please let me know.

Regards,

 

Alberto R
0 Kudos
MBrok1
Beginner
602 Views

Thanks Alberto, I will contact with Gigabyte support.

So... I don't need to run intel-sa-00075-console.exe with the -disableCCM option (CCM Disabled is False)?

0 Kudos
idata
Employee
602 Views

MikiBroki: You are very welcome, perfect.

 

 

Correct, you do not need to run that file. Hopefully Gigabyte will be able to provide the proper BIOS version to fix this problem.

 

 

Any questions, please let me know.

Regards.

 

Alberto R
0 Kudos
Reply