Hello,
I am about to scan our enviroment in order to check the status on the client. I downloaded the tool from .Download INTEL-SA-00075 Detection and Mitigation Tool . At first glance it seems to work correctly. The Gui version, the xml file and the console version shows the vulnerability status. The problem is about registry. The system information is missing.
How am I supposed to collect the inventory information at large scale if the vulnerability status is not written in registry ?
Here is the exported values from the registry
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\INTEL-SA-00075 Discovery Tool]
"Scan Date"="30/11/2017 13:34:52"
"Computer Name"="Test"
"Application Version"="1.0.1.39"
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\INTEL-SA-00075 Discovery Tool\Hardware Inventory]
"Computer Manufacturer"="HP"
"Computer Model"="HP ZBook 15 G3"
"Processor"="Intel(R) Core(TM) i7-6820HQ CPU @ 2.70GHz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Setup and Configuration Software\INTEL-SA-00075 Discovery Tool\ME Firmware Information]
"ME Version"="11.0.18.3003"
"ME Version Major"=dword:0000000b
"ME Version Minor"=dword:00000000
"ME Version Build"=dword:00000bbb
"ME Version Hotfix"=dword:00000012
"ME SKU"="Intel(R) Full AMT Manageability"
"ME Provisioning State"="Provisioned"
"ME Driver Installed"="True"
"LMS State"="NotPresent"
"Micro LMS State"="Running"
"EHBC Enabled"="False"
"Control Mode"="Admin"
"Is CCM Disabled"="False"
And from WoW3264 node
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Intel\Setup and Configuration Software\INTEL-SA-00075 Discovery Tool]
"Scan Date"="30/11/2017 13:34:52"
"Computer Name"="WPLCND708524T"
"Application Version"="1.0.1.39"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Intel\Setup and Configuration Software\INTEL-SA-00075 Discovery Tool\Hardware Inventory]
"Computer Manufacturer"="HP"
"Computer Model"="HP ZBook 15 G3"
"Processor"="Intel(R) Core(TM) i7-6820HQ CPU @ 2.70GHz"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Intel\Setup and Configuration Software\INTEL-SA-00075 Discovery Tool\ME Firmware Information]
"ME Version"="11.0.18.3003"
"ME Version Major"=dword:0000000b
"ME Version Minor"=dword:00000000
"ME Version Build"=dword:00000bbb
"ME Version Hotfix"=dword:00000012
"ME SKU"="Intel(R) Full AMT Manageability"
"ME Provisioning State"="Provisioned"
"ME Driver Installed"="True"
"LMS State"="NotPresent"
"Micro LMS State"="Running"
"EHBC Enabled"="False"
"Control Mode"="Admin"
"Is CCM Disabled"="False"
Any ideas ?
Thanks
Tomasz