			Revision History
			Q95 ROM Family


Models Supported:	HP ProBook x360 11 G3 Education Edition PC

[Security]
EntryME_PCR00=
FullME_PCR00= 9DCF4375A2654FFBB4B5D61A333E7E6DF444B852F009020FA02B475DC748050B



- This BIOS upgrade package also includes the following firmware:		(only list appropriate ones)                                                                               
Intel Trusted Execution Engine (TXE) 4.0.50.2083
Embedded Controller (EC) v50.2F.00
Intel VBIOS v13.0.1004
Intel GOP v13.0.1018
USB Type-C PD Firmware v7.11
Realtek PXE ROM v2.65

Version 01.26.00
ENHANCEMENTS:  
- Addresses security vulnerabilities CVE-2023-27502, CVE-2023-28389, CVE-2023-28746 and CVE-2023-32633.
FIXES:

Version 01.25.00
ENHANCEMENTS:  
- Updates the message that is displayed when a Non-HP Battery is detected.
- Provides support for the SMBIOS type1 version string for db addition.
- Enhances secure boot keys protection.
FIXES:
- Fixes issue that occurs after the EBAM and BIOS admin passwords are set where flashing the BIOS with the correct password causes the Firmware Update and Recovery Utility interface to display the message, Incorrect password was entered.
- Fixes an issue on a system that is in shutdown state while connected to a Type-C adapter where the system battery does not recharge and the charge status LED light is blinking.

Version 01.24.00
ENHANCEMENTS:  
- Addresses security vulnerabilities CVE-2022-29871
FIXES:



Version 01.23.00
ENHANCEMENTS:  
- Addresses security vulnerabilities CVE-2022-3602 and CVE-2022-3786.
- Adds support for Extended DHCP Timeout in the BIOS setup menu.
- Adds a setup option to control Extended DHCP Timeout for the pre-boot network experience.
FIXES:
- Fixes an issue where a POST Power-On Password cannot be set after a BIOS Administrator Password is set in Enhanced BIOS Authentication Mode.


Version 01.22.00
ENHANCEMENTS:  
- Enhancement to address security vulnerabilities CVE-2022-27541.
FIXES:
- Fixes issue where  BIOS Administrator password/Power on password can be accepted when the password length is less than Password Minimum Length.


Version 01.21.00
ENHANCEMENTS:  
- Enhancement to address security vulnerabilities CVE-2022-26845, CVE-2022-29893, CVE-2022-27497, CVE-2022-33159.
FIXES: 


Version 01.20.00
ENHANCEMENTS:  
- Enhancement to address security vulnerabilities CVE-2022-21233, CVE-2022-31635, CVE-2022-31636, CVE-2022-31637, CVE-2022-31638, CVE-2022-31639, CVE-2022-31640, CVE-2022-31641, CVE-2022-31642.
FIXES: 
- Fixes an issue where there is an unsupported option called "PCI Express Power Management" in bios configuration utility
- Fixes an issue where system enter Sleep Mode, then will auto wake after approx. 5 seconds. Will never reproduce with ANY device in USB-C port.


Version 01.19.00
ENHANCEMENTS:  
 - Enhancement to address security vulnerabilities CVE-2022-21151
FIXES: 


Version 01.18.20
ENHANCEMENTS:  
- Enhancement to address security vulnerabilities CVE-2022-23924, CVE-2022-23925, CVE-2022-23926, CVE-2022-23927, CVE-2022-23928, CVE-2022-23929, CVE-2022-23930, CVE-2022-23931, CVE-2022-23932, CVE-2022-23933, CVE-2022-23934.
- Enhancement to address security vulnerabilities CVE-2022-23953, CVE-2022-23954, CVE-2022-23955, CVE-2022-23956, CVE-2022-23957, CVE-2022-23958.
FIXES: 


Version 01.18.00
ENHANCEMENTS:  
- Enhancement to address security vulnerabilities CVE-2021-39297, CVE-2021-39299, CVE-2021-39300, CVE-2021-39301.
- Corrected battery capacity error observed when configured for "Maximize my battery health" is configured in the BIOS.
FIXES: 
- Fix ECRAM 0x7B bit 0 setting not correct when change to maximum my battery health.


Version 01.17.00
ENHANCEMENTS:  
- Support Micron 4Gb MT40A512M16TB-062E:R 3200 L31664-673 SPD 
- Enhancement to address security vulnerabilities CVE-2021-0146.      
FIXES: 
- Fixes issue where system stops at Network BIOS Update screen after execute network connection check and trigger "Update System BIOS" via F10 setup menu in legacy boot mode.
- Fixes issue where Bitlocker unlock over network intermittently failure on specific network configuration.
- Fixes an issue where charge LED  from amber change to white when battery charging to 88%


Version 01.16.02
ENHANCEMENTS:  
- Behavior change for system battery icon to show 100% instead of 80% when battery is fully charged to align with industry battery behavior expectations when using F10 setting for Maximize My Battery Health?
- Adds new wifi card CAVA support.
- Adds new memory module support.        
FIXES: 
- Fixes issue where some F10 settings or help message display incomplete when change to non-English language.
- Fixes issue where an error message pops up (0x8007054F) while enable Power-On Authentication if user account name longer than 11 characters.


Version 01.15.00
ENHANCEMENTS:  
- Adds a feature "IPv6 during UEFI Boot" in F10 setup interface where user has ability to disable IPv6 during preboot phase.
- Enhancement to address security vulnerabilities CVE-2020-24506 and CVE-2020-24507, CVE-2020-24516.
- Enhancement to address security vulnerabilities CVE-2020-24513, CVE-2020-24489.         
FIXES: 
- Fixes issue where Security Device Error message pop out after enable Power-on Password.


Version 01.14.00
ENHANCEMENTS:  
- Update Intel reference code to 2.2.1.3.         
FIXES: 
- Fixed an interoperability issue seen with an Apple XDR monitor.
- Fixed an issue that is observed with Audio accessory devices with a failure rate.

Version 01.13.01
ENHANCEMENTS:  
- Addresses security vulnerabilities CVE-2020-8695, CVE-2020-8694.
- Addresses security vulnerabilities CVE-2020-8705, CVE-2020-8744, CVE-2020-8745, CVE-2020-8750, CVE-2020-12297, CVE-2020-12303, CVE-2020-12355.
- Adds public WMI support to get battery information via third party software.         
FIXES: 
- Fixes an issue where the charge LED status light continues to flash after the battery is fully charged.
- Fixes an issue where Secure Erase does not execute properly when the display is changed to a non-English language.
- Fixes an issue where the system resumes from sleep slower than expected when the Video Memory is changed to 512 MB. 
- Fixes an issue where the Windows Hotkey function are activated when certain letters (such as Q, W, or E) are pressed after function keys F1 to F5 are pressed continuously.
- Fixes an issue where an HP USB-C Dock G5 connected to the system stops functioning when the Thunderbolt system resumes from Hibernation.


Version 01.12.00
ENHANCEMENTS:  
- Enhancement to address security vulnerabilities CVE-2020-8672.
- Adds a feature "Wake on LAN Power-on Password Policy" in F10 setup interface.
- Adds a feature "Allow User to Modify Power-on Password" in F10 setup interface.
FIXES:  
- Fixes an issue where message of Physical Presence Interface display incomplete when change to Non-English language. 
- Fixes an issue where system unexpected hang up when a EFI folder is created in Recovery partition.
- Fixes an issue where Physical Presence Interface cannot set to disable when change to non-English language in F10 setup interface.
- Fixes an issue where original boot entry is deleted while third party encryption software creates their own boot entry.
- Fixes an issue where Automatic DriveLock option is enabled and greyed out after the BIOS Administrator Password is removed.
- Fixes an issue where system does not boot to OS directly when choose "Postpone this BIOS until the next Reboot" option at scheduled BIOS update via F10 setup interface.


Version 01.11.00
- Fixes issue where system unexpected shutdown intermittently when battery is in ship mode state and press power button too soon (within around 5sec) after plugging AC adapter.

- Fixes an issue where system no pop up warrning message in windows when USBC port over current protection event occured in hibernate or system off state.

- Fixes an issue where system cannot enable "Automatic Drivelock" after placing a hard drive into another system and disabling Automatic Drivelock by another system.

- Fixes an issue where cannot enable "Automatic DriveLock" option for NVMe SSD after "create BIOS Administrator password" in F10.

- Fixes an issue where system does not prompt for Power on Authentication with BIOS Administrator and POST Power-On Password options when schedule update check is failed.

- Fixes an issue where system firmware is updated from recovery partition instead of EFI partition.

- Fixes an issue where hard drive still prompt DriveLock password after forcing the Master password to match BIOS Administrator Password.

- Fixes an issue where original boot entry is deleted while third party encryption software creates their own boot entry

- Fixes an issue where system unexpectedly pop up ""Enter current DriveLock Password"" when enable Automatic Drivelock then restart system several times.

- Fixes an issue where Automatic DriveLock option is enabled and greyed out after BIOS Administrator Password is removed.

- Fixes an issue where original boot entry is deleted while third party encryption software creates their own boot entry.

- Fixes an issue where system firmware is updated from recovery partition instead of EFI partition.

- Fixes an issue where hard drive still prompt DriveLock password after forcing the Master password to match BIOS Administrator Password.

- Fixes an issue where system cannot enable ""Automatic Drivelock"" after placing a hard drive into another system and disabling Automatic Drivelock by another system.

- Fixes an issue where cannot enable ""Automatic DriveLock"" option for NVMe SSD after ""create BIOS Administrator password"" in F10.

- Fixes an issue where system does not prompt for Power on Authentication with BIOS Administrator and POST Power-On Password options when schedule update check is failed."

- Changes the default setting of the HP Battery Health Manager in the BIOS Settings from Maximize My Battery Duration to Let HP Manage My Battery Health. The new default setting dynamically changes how the system charges the battery based on usage conditions over time to provide optimal battery health

- Adds Drivelock password feature support on OPAL SED NVMe SSD.

- Enhancement to address security vulnerabilities CVE-2020-0531, CVE-2020-0532, CVE-2020-0533, CVE-2020-0535, CVE-2020-0536, CVE-2020-0537, CVE-2020-0538, CVE-2020-0539, CVE-2020-0540, CVE-2020-0541, CVE-2020-0545

PCR0 (TPM2.0) = 039681A3823944FFD62FA0CBB58B52D4CBE891DBADA4DF0D0292BE755E4D9080

Version 01.10.00
- Fixes an issue where the special symbol display is not correct if the F10 setup interface is changed to the Russian language.

- Fixes an issue which causes the system to boot slower than expected when a network cable is used to connect the system to a Dell or a Targus USB Display Link Dock.

- Fixes an issue that occurs on a system that is configured to run updates from a proxy server. The BIOS does not update and the system displays the error message, Failed to determine if new BIOS is available, when the update is run without setting the Proxy Server in F10 setup interface.

- Fixes an issue where the system prompts for Power on Authentication with BIOS Administrator and POST Power-On Password options before a scheduled BIOS update is run.

- Adds a feature to support Automatic DriveLock in F10 setup interface for Pyrite NVMe SSD.

- Adds hidden hotkeys that are activated by pressing Fn+E for the insert function and Fn+W for the pause function.

- Updates the CPU microcode for Intel processors to version 0x32.

- Updates the Intel silicon reference code to version 3.7.5 to enhance compatibility.

PCR0 (TPM2.0) = 3665BF7787E4874A8990EE3D5924ECBF3E1D9B5D4A5362CE01B0D889F7B857B5

Version 01.05.00 
- Fixes issue where specific SanDisk USB drive does not be listed in F9 Boot Menu.

- Fixes issue where system intermittently enters hibernation after idle around 2 hours in battery mode when HP Sure Run and Bitlocker is enabled.

- Fixes issue where system reports error "Failure during data transfer (maximum downloaded content size exceeded)" when unit tries to update firmware via FTP server with proxy from F10 setup interface.

- Enhances the feature "Battery Health Manager" to control the battery charging behavior bases on usage to prevent swelling.

- F10 menu "Dynamic Platform and Thermal Freamwork" add help to remind the driver name changed to "Intel Dynamic Tuning".

- Modify the Description of PD Firmware Update on updating screen to USB-C Controller Firmware as the marketing naming.

- Updates Cypress PD firmware  to v7.10 for compatibility enhancement.

- Adds a feature to support Enhanced Secure Erase command for ATA drive in F10 setup interface.

- Adds a feature to query DriveLock setting by HP BIOS Configuration Utility (BCU).

- Adds a feature to seprate Administrator/User DriveLock password in F10 setup interface.

- Provides the following firmware:

PCR0 (TPM2.0) = 1875ECA071EFD95016576B2558C7B440AD4F0C7BA4C0EBFB7B890F14EAB4CE68


Version 01.04.00 
- Fixes an issue under the UEFI Boot Order where the IPV4 Network/IPV6 Network do not have the prefix label, NETWORK BOOT.

- Fixes an issue which causes the system to power on slower than expected when an NVIDIA GeForce RTX 2070/2080 Graphics card is installed on the system.

- Fixes an issue that occurs when a system has the BIOS password enabled in the F10 setup and Power-on Authentication is enabled in HPCSM. After the BIOS Administrator at Power-on-Authentication option is subsequently deselected in the F10 setup interface, the system displays the message, Authentication Failed.

- Fixes an issue where the display of the TPM Firmware Update interface is cut off during the update process.

- Fixes an issue that occurs when the update schedule is set to daily/weekly/monthly where a BIOS update via the F10 setup interface fails and the system displays the message, Internal error.

- Fixes an issue where the SystemDiags.log file cannot be created in the FTP server after Remote HP PC Hardware Diagnostics are executed.

- Fixes an issue where a bootable USB storage device on an external dock connected to the system is not detected in the F9 boot menu.

- Removes the multi-processor enable/disable option from the BIOS F10 setup.

- Adds an option in the F10 setup to download and install BIOS updates automatically without prompts.

- Adds the Native OS Firmware Update Service feature to the F10 setup interface to enable and disable firmware updates using the Window Update service.

PCR0 (TPM2.0) = 91CEEFBDD1BEB5424D07FEFC978509379ABCA4B07C6B84E55E1E31B3E46DFB4A

Version 01.03.00 	
- Enhancement to address security vulnerabilities CVE-2018-12126, CVE-2018-12127, CVE-2018-12130.                                                                                                                                                                                         
- Enhancement to address security vulnerabilities CVE-2019-0086, CVE-2019-0090, CVE-2019-0091, CVE-2019-0092, CVE-2019-0093, CVE-2019-0094, CVE-2019-0096, CVE-2019-0097, CVE-2019-0098.


PCR0 (TPM2.0) = E16C89773EB083E0B6AC09A8F56F873ABFFCFA452CF294332D55E4C4009E86B5
               




