KB5029778 How to manage CVE-2022-40982 "Downfall" CPU vulnerability


  • Staff

KB5029778: How to manage the vulnerability associated with CVE-2022-40982​


Introduction

Microsoft is aware of a new transient execution attack named gather data sampling (GDS) or "Downfall." This vulnerability could be used to infer data from affected CPUs across security boundaries such as user-kernel, processes, virtual machines (VMs), and trusted execution environments.

For more information about this vulnerability, see INTEL-SA-00828 security advisory and CVE-2022-40982.

Mitigate the vulnerability

IMPORTANT The mitigation described in this article is Enabled by default with the option to disable it. We recommend that you mitigate the vulnerability as soon as possible.

Note Intel’s latest products including Alder Lake, Raptor Lake, and Sapphire Rapids, have defense-in-depth measures in place and are not affected by this vulnerability.

To mitigate the vulnerability associated with CVE-2023-40982, install the Intel Platform Update (IPU) 23.3 microcode update. Typically, you need to obtain this update from your original equipment manufacturer (OEM). For a list of OEMs, see System Manufacturers. No further action to mitigate the vulnerability is required.

IMPORTANT We continue to work with Intel on their Gather Data Sample (GDS) Microcode and CPU support. Please refer to Intel for the most up-to-date information on GDS related Microcode and Firmware support from OEMs.

Disable the mitigation

If you do not consider GDS to be part of your threat model, you might choose to turn off (disable) the mitigation in a bare-metal environment.

Note Disabling the mitigation when Hyper-V (Virtualization) is enabled is not in scope of this current implementation.

To disable the GDS mitigation in Windows, you must have the following installed, as appropriate for your environment:
  • On supported Windows 10 and Windows 11 environments, you must have installed the Windows update dated on or after August 22, 2023.
  • On supported Windows Server environments, you must have installed the Windows update dated on or after September 12, 2023.
After the appropriate Windows update is installed, you must set the following feature flag in the registry:

Registry location: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
Value name: FeatureSettingsOverride
Value type: REG_DWORD
Value data: 0x2000000 (hex)

If this registry value does not already exist, run the following command to disable the GDS mitigation:

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 33554432 /f


References

Gather Data Sampling Technical Paper

Threat Analysis Assessment for GDS Paper

Gather Data Sampling Performance Data Analysis Paper

Intel Security Advisory: INTEL-SA-00828

Source:
 

Attachments

  • Windows_Security.png
    Windows_Security.png
    6 KB · Views: 0
Last edited:

Change log

Change dateChange description
September 1, 2023Removed the content to disable the GDS mitigation as that option is no longer available
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP Spectre x360 2in1 14-eu0098nr (2024)
    CPU
    Intel Core Ultra 7 155H 4.8 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Graphics card(s)
    Integrated Intel Arc
    Sound Card
    Poly Studio
    Monitor(s) Displays
    14" 2.8K OLED multitouch
    Screen Resolution
    2880 x 1800
    Hard Drives
    2 TB PCIe NVMe M.2 SSD
    Internet Speed
    Intel Wi-Fi 7 BE200 (2x2) and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender and Malwarebytes Premium

Latest Support Threads

Back
Top Bottom