Infineon Technologies Trusted Platform Modules (TPM v2.0), Security Feature Bypass Vulnerability Windows Installation Procedure



Document ID: 4015902

 

Posted Date: 2017-11-14

 

Last Updated: 2017-11-14

 

Distribution: View Public Website

 

Issue

 

The purpose of this software is to update the firmware of Infineon Technologies Trusted Platform Module v2.0.

 

Procedure

WARNING:  Before starting this update, it is strongly recommended that you backup your computer. If you are required to clear the TPM owner, note that the TPM will be reset back to factory defaults and you will lose created keys and the data protected by those keys.

IMPORTANT NOTERefer to Microsoft® Security TechCenter document before clearing & resetting TPM keys: (https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV170012)

Prerequisites:

  • System BIOS need to be at the latest version as posted on the Toshiba Support Site.
  • To run the TPM Firmware update tool, administrative privilege are required.

How to update the TPM firmware

Following step is for updating of the TPM firmware.

  1. Confirm the information of TPM device.
    1. To verify the TPM version, type following command to launch TPM management tool: “tpm.msc”
      1. Please refer to the related information for this confirmation. (Document ID: 4015874)
    2. If the TPM device is in the scope then go to the next step for updating the firmware.
  2. Verify the version of BIOS is latest.
    1. BIOS update is necessary to execute the firmware update tool if it is older than the specified version.
      1. Please refer to the related information for this confirmation. (Document ID: 4015874)
  3. Plug-in AC adapter and confirm the battery remain level is enough.
  4. Download the package of the tool from the web site.
    1. TPM 2.0 Firmware Download Document ID: 4015895
    2. Program name: TPM FW Update Tool
    3. Version: 1.0.0.4
  5. Launch the tool as administrator privilege.
  6. Confirm the UI and proceed to start the firmware update.
    1. If the version of BIOS is not latest for supporting TPM firmware update, following message shows.
      1. “The BIOS needs to be updated before updating the TPM FW. Please check the TOSHIBA website for the latest BIOS.”
      2. Please push “Exit” button to close this tool and update BIOS first.
    2. If the firmware was already updated, following message shows.
      1. “This TPM FW version is up to date. This system is NOT Vulnerable”
        1. In this case, the firmware update is not necessary. Please push “Exit” button to close this tool.
    3. If the firmware update is not ready now, please cancel the step and wait for the future information.
  7. The system will need to be rebooted to start the firmware update process.
    1. Click on “Restart Now” button.
  8. After the TPM firmware has been updated the system will automatically restart again to completed to process.
  9. After logging into the system the tool will shows the result of the firmware update. (Only if the same user logs back in)
    1. The tool shows successful message as below if update has passed.
      1. “The TPM FW Update is successful”
      2. To confirm the version information of the TPM firmware, type following command to launch TPM management tool: “tpm.msc”
        1. TPM version change to the information listed on table below.

Manufacturer Name

Manufacturer Version

Specification Version

IFX

5.62.3126.x

2.0

 

  1. The tool shows failure message as below if update has failed.
    1. “The TPM FW update has failed. Please check the log for details.”
Export Control and EULA
Use of any software made available for download from this system constitutes your acceptance of the Export Control Terms and the terms in the Dynabook end-user license agreement both of which you can view before downloading any such software.