Menu
Microsoft issues update to disable Spectre Variant 2 patch

Microsoft issues update to disable Spectre Variant 2 patch

Vendor steps in while Intel continues to investigate impact of current microcode version

Credit: Dreamstime

Microsoft issued an update over the weekend to disable mitigation against Spectre Variant 2 found on Intel chips.

Following Intel’s recommendation for customers to stop deploying a set of faulty patches it issued to fix security flaws in its chips, Microsoft released the update on 27 January.

“We understand that Intel is continuing to investigate the potential impact of the current microcode version and encourage customers to review their guidance on an ongoing basis to inform their decisions,” Microsoft wrote in its support page.

The update (KB4078130) disables the mitigation against CVE-2017-5715 – branch target injection vulnerability only. This was the microcode released by Intel in order to address Spectre Variant 2.

Intel found that this microcode could cause more reboots than expected and other “unpredictable system behaviour”, which in result could cause data loss or corruption.

Microsoft’s update is meant to prevent that behaviour.

“If you are running an impacted device, this update can be applied by downloading it from the Microsoft Update Catalog website,” Microsoft wrote.

The update covers Windows 7 (SP1), Windows 8.1, and all versions of Windows 10, for client and server.

“As of January 25, there are no known reports to indicate that this Spectre variant 2 (CVE 2017-5715) has been used to attack customers,” Microsoft wrote. “We recommend Windows customers, when appropriate, reenable the mitigation against CVE-2017-5715 when Intel reports that this unpredictable system behaviour has been resolved for your device.”

Microsoft is also offering the option to manually disable and enable the mitigation against Spectre Variant 2 to advanced users on impacted devices.

On 3 January, Intel announced that a design flaw in its microprocessors left systems vulnerable.

The Spectre flaw affected nearly every modern computing device, including those with chips from Intel, Advanced Micro Devices (AMD) and ARM Holdings.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Microsoftintelpatchmeltdownsecurity flawspectrechip flaw

Brand Post

Featured

Slideshows

Malwarebytes shoots the breeze with channel, prospects

Malwarebytes shoots the breeze with channel, prospects

A Kumeu, Auckland, winery was the venue for a Malwarebytes event for partner and prospect MSPs - with some straight shooting on the side. The half-day getaway, which featured an archery competition, lunch and wine-tasting aimed at bringing Malwarebytes' local New Zealand and top and prospective MSP partners together to celebrate recent local successes, and discuss the current state of malware in New Zealand. This was also a unique opportunity for local MSPs to learn about how they can get the most out of Malwarebytes' MSP program and offering, as more Kiwi businesses are targeted by malware.

Malwarebytes shoots the breeze with channel, prospects
EDGE 2019: Channel forges new partnerships during evening networking

EDGE 2019: Channel forges new partnerships during evening networking

Partners, vendors and distributors reconnected during a number of social gatherings during EDGE 2019. The first evening saw the channel congregate for a welcome party at the Hamilton Island yacht club, while the main poolside proved to be the perfect stop for a barbecue on the final night.

EDGE 2019: Channel forges new partnerships during evening networking
Show Comments