[H760] Applying the Intel firmware vulnerability fix using Windows PE?

Moderator: ModTeam

telcoM
Posts: 3
Joined: Tue Jun 06, 2017 11:19
Product(s): CELSIUS H720, CELSIUS H760

[H760] Applying the Intel firmware vulnerability fix using Windows PE?

Postby telcoM » Wed Jun 07, 2017 10:59

I'm currently running Linux (Debian 8 + customized kernel 4.9.30) on my CELSIUS H760. Yes, I know it's unsupported, but it has worked pretty well for me so far. However, the BIOS updates can be tricky.

The previous BIOS updates were easy enough to install using Windows PE: the Windows version of the update ran on 32-bit Windows PE, so I could just prepare a bootable USB stick or even a network boot configuration on a PXE server and use that to update the BIOS.

But the new BIOS 1.19 that was released as a fix for the Intel firmware vulnerability (CVE-2017-5689) seems to be available only as an Admin Pack. It includes an updater that is supposed to be runnable from Windows, and files & instructions for creating a FreeDOS-based bootable USB stick for another update method.

The FreeDOS-based updater told me that "secure BIOS" is enabled and so the DOS-based updater cannot perform the update. And the Windows-based Update_.exe in the Admin Pack starts but immediately displays a dialog "Unknown error, please contact support".

Has anyone successfully installed the BIOS 1.19 using any sort of USB-stick or network boot?

Or does anyone have any idea what the Windows-based Update_.exe from the Admin Pack technically requires to run successfully? Perhaps I just need to add some drivers to the Windows PE environment?

telcoM
Posts: 3
Joined: Tue Jun 06, 2017 11:19
Product(s): CELSIUS H720, CELSIUS H760

Re: [H760] Applying the Intel firmware vulnerability fix using Windows PE?

Postby telcoM » Fri Jun 09, 2017 10:56

The exact error dialog text from the BIOS 1.19 Admin Pack Update_.exe was:
---------
System Firmware Update Utility

Exit with unknown error.
Contact your Fujitsu support representative.

[OK]
---------
And that happened with 32-bit Windows PE based on Windows version 10.0.15063.0, even with all the optional WinPE components and the HECI driver added to it.

Since the 64-bit Windows PE does not include 32-bit compatibility (i.e. it requires that all binaries are 64-bit), the Update_.exe does not run at all under 64-bit version of Windows PE.

telcoM
Posts: 3
Joined: Tue Jun 06, 2017 11:19
Product(s): CELSIUS H720, CELSIUS H760

Re: [H760] Applying the Intel firmware vulnerability fix using Windows PE?

Postby telcoM » Fri Jul 28, 2017 11:23

I found a workaround.
Disabling the internal SSD drive in BIOS and plugging in an eSATA drive allowed me to set up a temporary minimal Windows installation with the required drivers.

Once the update was done, I removed the extra boot order option added by the Windows installer, re-enabled the internal drive and unplugged the eSATA drive. Back in business with the firmware fix in place, without interfering with the existing installation in any way.


Return to “CELSIUS Mobile Workstations”

Who is online

Users browsing this forum: No registered users and 0 guests

cron