Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Oldest
  1. Anonymous
    2018-01-18T03:16:11+00:00

    I know they have been working on a fixed patch so hopefully this one will not cause problems. Haven't gotten the patch yet. Will get back to this thread when it gets installed.

    EDIT

    Maybe I don't get that patch. I have 1709 installed

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-18T03:30:15+00:00

    Hi Alexito

    right - that patch is for WIN ver 1703

    HENRY

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-01-19T07:23:32+00:00

    An interesting letter from a congressman to Intel and others about Meltdown and Spectre. Heats on.

    https://www.theverge.com/2018/1/16/16898094/meltdown-spectre-vulnerability-letter-congress-intel-amd-arm

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-19T16:23:47+00:00

    The list of the new updates from Microsoft:

    Windows Server 2016 – KB4057142

    Windows Server 2012 R2 – KB4057401

    Windows Server 2012 – KB4057402

    Windows 10 1709 – KB4073290

    Windows 10 1703 – KB4057144

    Windows 10 1607 – KB4057142

    Windows 8.1 – KB4057401

    That fix several issues, specially the issues with Symantec AV that was holding up the patches.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-23T18:36:57+00:00

    And just when we thought that we were seeing the end of this, Intel posted this:

    Intel Security Issue Update: Addressing Reboot Issues

    Broadwell and Haswell platforms send ugly reboots when firmware updates are applied.

    And give an update just yesterday:

    Root Cause of Reboot Issue Identified; Updated Guidance for Customers and Partners

    that basically says "stop deployment".

    Just great!.

    Was this answer helpful?

    0 comments No comments