Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Newest
  1. Anonymous
    2018-01-08T22:10:15+00:00

    So, basically, we're agreeing it all depends on your priorities, then 😎

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-08T19:50:51+00:00

    Well, We still are on HOLD until Symantec certify that is ready to be deployed.

    For all what is worth. Microsoft released a PowerShell script to validate if you are covered or not.

    Speculation Control Validation PowerShell Script

    NOTE: At least for 2 out 3:

    ADV180002 Advisory include 3 vulnerabilities:

    CVE-2017-5753 - Bounds check bypass

    CVE-2017-5715 - Branch target injection

    CVE-2017-5754 - Rogue data cache load

    CVE-2017-5715 and CVE-2017-5754 are check with this script, CVE-2017-5753 is not.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-01-08T18:52:13+00:00

    I guess I'm as calm as I can be having a BSOD with a root cause of CPU Cache :-P.  Staying cautious and testing updates on DEV/TEST Machines first would be wise until this is all sorted (Since it's already caused a couple of my servers to have issues initially on boot, which was found to be due to AV).  Your firewalls, IP Reputation checks, IDS/IPS, etc. should keep you protected relatively well. 

    Some gamers actually posted some benchmark statistics on how this patch has affected some games performance, along with some other applications, it makes an interesting read.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-08T18:32:03+00:00

    OK. First everyone needs to calm down. The latest "Big Bad" isn't here yet.

    And Microsoft, Intel, Dell, and HP (among others) have (and are continuing to release) patches  & updates that address the issue with side channel exploits.

    Now, while some continue to advise people to wait to apply any of these I would, personally, continue to suggest just the opposite.

    Apply the fixes as and when they become available.

    PARTIAL protection is better than NONE.

    And while you're waiting to see if the patches and updates are safe and trouble free some hacker could begin quietly stealing your data. Timing really IS everything.

    Remember all those people whose computers had been turned into zombies by botnets a decade ago?

    This could well be worse than that.

    So...does the Microsoft Patch released on January 4th significantly slow down your computer? Not in my experience.

    But that will depend a good deal on whether you keep up to date with your Computer Manufacturer and if your Anti-Malware program of choice is compatible.

    Windows Defender Security Center already is and other companies are hard at work resolving conflicts.

    So check with your A/V provider to ensure compatibility before you download.

    Or switch to Windows Defender if you don't want to wait.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-08T18:30:04+00:00

    I'm using Symantec.  We have updated the engines on all of them, and I'm no longer getting this...looks to be a one time thing so far.  I have had 1 Server 2012 VM hang on boot before we updated the Symantec engines and all seems to be OK for now.

    Was this answer helpful?

    0 comments No comments