Advisory
https://www.intel.com/content/www/us/en/support/articles/000025619/software.html
Tool
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
A lot of noise on the internet, after Intel confirm that chips have a bug:
https://newsroom.intel.com/news/intel-responds-to-security-research-findings/
This post is to bring some light on this.
1- Intel says is not only their chips affected
2- PCID (Process-Context Identifiers), a chip feature, has a bug that allow apps (malware) to read data
3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.
4- Macintosh and Linux OS are also affected.
Rumors:
1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled.
2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.
2- Still if you have older CPU, performance will be affected worse than newer CPUs.
3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)
Just as I'm writing this, Linus Torvalds and his team are working on this too:
https://lkml.org/lkml/2018/1/2/703
https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de
Can we get a word from Microsoft?
For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)
Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)
If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)
Please, any info will be appreciated.
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Oh well... What to say...
In my personal opinion it would be wise to wait and see what damage those MS patches make... There are quite a few reports of weird happenings out there...
BUT: That is only my personal opinion.
I'm just a normal user....
To summarize:
1- Make sure your Antivirus is certified for the Jan 2018 updates. Update your AV.
2- Verify the reg keys listed on the MS document are set. (seems like on server OS has to be done manually)
3- Install the MS updates.
4- Install your hardware updates (when are available)
Seems right?
Valdemar, reading this document:
Mentions:
Customers should take the following actions to help protect against the vulnerabilities:
Important Customers who only install the Windows update will not receive the benefit of all known protections
So, that means that even after patching we still not safe?
Or windows defender will do the registry changes?
What about the rest of us that we have a different AV?
I am still waiting for Dell to release firmware.