Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Newest
  1. Anonymous
    2018-02-02T16:10:18+00:00

    Some Bad news, Intel is still to release updates, and 

    Meltdown-Spectre: Malware is already being tested by attackers

    http://www.zdnet.com/article/meltdown-spectre-malware-is-already-being-tested-by-attackers/

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-27T23:35:56+00:00

    Have a feeling the end won't be in sight anytime soon. Even with proper Bios  updates. this vulnerability has far reaching roots. Hardware, software . Just a mess . I have my Acer laptop sitting in a faraday cage because it has the AMT. . It was just a very cheap laptop with Windows 10 home to use with my printer . No updates for it until middle of March. Geez.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-01-26T00:42:11+00:00

    What other are saying is correct.

    Dell posted that removed the BIOS updates affected, but still recommend to install the Win OS patches.

    Microprocessor Side-Channel Vulnerabilities (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on Dell products

    Update 01/22/2018:

    Intel has communicated new guidance regarding the "reboot issues" with the microcode included in the BIOS updates released to address Spectre (Variant 2), CVE-2017-5715. Dell is advising that all customers should not deploy the BIOS update for the Spectre (Variant 2) vulnerability at this time. We are removing the impacted BIOS updates from the web and suspending further BIOS updates for affected platforms.

    If you have already applied the BIOS update, please wait for further information and an updated BIOS release, no other action is recommended at this point. Please continue to check back for updates.

    As a reminder, the Operating System patches are not impacted and still provide mitigations to Spectre (Variant 1) and Meltdown (Variant 3). The microcode update is only required for Spectre (Variant 2), CVE-2017-5715.

    Damn, when we are going to see the end of this mess?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-25T18:11:07+00:00

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-25T01:26:34+00:00

    Sadly it is not just computers that are affected but any newer technology that has a chip installed. I am so happy I drive an old car.

    https://www.theatlantic.com/technology/archive/2018/01/spectre-meltdown-cybersecurity/551147/

    Was this answer helpful?

    0 comments No comments