Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Newest
  1. Anonymous
    2018-01-04T23:04:04+00:00

    Well, Symantec reports problems even with the ERASER engine 117.3:

    Endpoint Protection system tray icon reports there are multiple errors after updating ERASER to 117.3.0 and Microsoft Update KB4056892

    Just great!

    For now, anyone with Symantec AV just hold on.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-04T21:28:53+00:00

    Just meant as an info... because IMO below articles are worth reading and contain lots of further info/links:

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-01-04T19:52:21+00:00

    Just to add that also affects Windows servers OS: Windows Server 2016, Windows Server 2012, Windows Server 2008 and all R2.

    https://support.microsoft.com/en-us/help/4072698/windows-server-guidance-to-protect-against-the-speculative-execution

    Some KBs are still in process and not released yet.

    Also affects SQL Servers: SQL Server 2008, SQL Server 2008R2, SQL Server 2012, SQL Server 2014, SQL Server 2016, SQL Server 2017:

    https://support.microsoft.com/en-us/help/4073225/guidance-for-sql-server

    Read more here:

    ADV180002 | Guidance to mitigate speculative execution side-channel vulnerabilities

    https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-04T17:01:07+00:00

    Once more...just to be clear. This is not a virus.

    This is a bug.

    It is not really that big an issue at the moment though it is expected to be in the future.

    The Microsoft Cumulative Security Update that addresses this is available NOW.

    Just go to settings and click update. Then check for updates.

    Also visit HP, Dell, any manufacturer of your device's website for other updates involving MELTDOWN and/or SPECTRE.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more