Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Newest
  1. Anonymous
    2018-04-27T17:03:39+00:00

    Microsoft released firmware for more Intel Processors.

    https://support.microsoft.com/en-sg/help/4091666/kb4091666-intel-microcode-updates

    Some notes:

    KB only applies for Win 10. 

    KB only protect after patched Windows is running. If you have another OS or you reinstall Windows, patch needs to be reinstalled.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-04-04T15:46:44+00:00

    Some news, bad news.

    Intel finally said that won't patch some chips, even though they are affected.

    Intel microcode revision guidance

    Isn't it great?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-03-09T21:44:15+00:00

    Yes I have ran both the SA-00086 and the GRC tool and both say I am patched. I have not tried the others. I do seem to have a problem that I have been unable to resolve and I am not sure what the problem is. I get report from SA-00086 tool that the intel capability licensing client is obsolete so until I can find a fix I have disabled the service. Maybe Windows is blocking the driver update for intel management . I have reinstalled the driver many times and still can't get the capability licensing to update.. Everything else has gone fine. Otherwise reports I am not at risk.I have found threads on this in a few forums but no definite answer. The intel management engine firmware and software is updated by Dell. Maybe the new BIOS microcode will take care of this. I too am waiting on Bios updates for my Dell and an Acer laptop. Wish there was a temporary patch for Kaby Lake. I have my Acer totally disconnected until Bios update because it reports vulnerable .

    I also noticed that there are 2 versions of the microsoft patch. X64 and another that does not state anything so it must be x32 patch.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-03-09T00:59:05+00:00

    Thanks for the update!

    Question for ConiGL : Have you have a chance to run any of the tools for Meltdown and Spectre vulnerabilities? Result is you are Patched?

    I want to see which tool works (Ashampoo, Gibson Research Corporation, MS Windows Analytics, the MS Powershell script?)

    I was reading more about the KB4090007:

    KB4090007 will check if you have the OS and CPU compatible. More CPU are going to be added.

    This MS update is a workaround until the BIOS is updated.  This KB does not affect the hardware and only protects when the patched OS is up and running.

    Updating the CPU with a new BIOS is the permanent solution.

    Means that if you reinstall your Windows OS without reapplying the Windows update, then your system will revert to being unprotected. Same if have dual boot with another OS.

    Nevertheless, this patch is better than no BIOS updates.

    We are also waiting for DELL to release the new BIOS firmwares!!... 

    Anytime, DELL!

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-03-08T19:02:46+00:00

    Hi, just want to inform anyone looking here that I installed the Microsoft microcode  update this morning on my Intel 6300 HQ skylake processor on my Dell 7559 laptop and had no problems with the update. I decided to make a system backup and proceeded with the update until I see a new BIOS from Dell. Do be sure to backup or make system restore point. The update shows in installed updates and can be uninstalled if there are problems. Good luck all.

    Post on the update. Thanks Alexito.

    Alexito_RG replied on

    If I read correctly, looks like now Microsoft is including  Intel firmware updates on this KB4090007:

    Today, Microsoft will make available Intel microcode updates, initially for some Skylake devices running the most broadly installed version of Windows 10 — the Windows 10 Fall Creators Update v 1709 — through the Microsoft Update Catalog, KB4090007.

    https://support.microsoft.com/en-us/help/4090007/intel-microcode-updates

    And also is warning about risks with AV compatibility.

    https://blogs.windows.com/windowsexperience/2018/03/01/update-on-spectre-and-meltdown-security-updates-for-windows-devices/ 

    Be careful when you authorize patches!

    Was this answer helpful?

    0 comments No comments