{"id":2537,"date":"2018-03-20T04:30:05","date_gmt":"2018-03-19T21:30:05","guid":{"rendered":"https:\/\/humanit.asia\/?p=2537"},"modified":"2019-07-22T15:08:40","modified_gmt":"2019-07-22T08:08:40","slug":"ta18-004a","status":"publish","type":"post","link":"https:\/\/old.humanit.asia\/th\/ta18-004a\/","title":{"rendered":"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance"},"content":{"rendered":"<p>Original release date: January 04, 2018 | Last revised: February 10, 2018Systems Affected<br \/>\nCPU hardware implementations<br \/>\nOverview<br \/>\nOn January 3, 2018, the National Cybersecurity and Communications Integration Center (NCCIC) became aware of a set of security vulnerabilities\u2014known as Meltdown and Spectre\u2014that affect modern computer processors. These vulnerabilities can be exploited to steal sensitive data present in a computer systems&#8217; memory.<br \/>\nDescription<br \/>\nCPU hardware implementations are vulnerable to side-channel attacks, referred to as Meltdown and Spectre. Meltdown is a bug that &#8220;melts&#8221; the security boundaries normally enforced by the hardware, affecting desktops, laptops, and cloud computers.\u00a0Spectre is a flaw an attacker can exploit to force a program to reveal its data. The name derives from &#8220;speculative execution&#8221;\u2014an optimization method a computer system performs to check whether it will work to prevent a delay when actually executed. Spectre affects almost all devices including desktops, laptops, cloud servers, and smartphones.More details of these attacks can be found here:Common Vulnerability and Exposure (CVE):Rogue Data Cache Load: CVE-2017-5754 (Meltdown) https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5754Bounds Check Bypass: CVE-2017-5753 (Spectre) https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5753Branch Target Injection: CVE-2017-5715 (Spectre) https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5715CERT\/CC\u2019s Vulnerability Note VU#584653Impact<br \/>\nAn attacker can gain access to the system by establishing command and control presence on a machine via malicious Javascript, malvertising, or phishing. Once successful, the attacker\u00a0could escalate privileges to exploit Meltdown and Spectre vulnerabilities, revealing sensitive information from a computer\u2019s kernel memory, including keystrokes, passwords, encryption keys, and other valuable information.<br \/>\nSolution<br \/>\nMitigationNCCIC encourages users and administrators to refer to their hardware and software vendors for the most recent information. In the case of Spectre, the vulnerability exists in CPU architecture rather than in software, and is not easily patched; however, this vulnerability is more difficult to exploit.\u00a0After patching, performance impacts may vary, depending on use cases. NCCIC recommends administrators ensure that performance is monitored for critical applications and services, and work with their vendor(s) and service provider(s) to mitigate the effect, if possible.Additionally, NCCIC recommends users and administrators who rely on cloud infrastructure work with their CSP to mitigate and resolve any impacts resulting from host OS patching and mandatory rebooting.For machines running Windows Server, a number of registry changes must be completed in addition to installation of the patches.\u00a0 NCCIC recommends verifying your Windows Server version before downloading applicable patches and performing registry edits.\u00a0 A list of registry changes can be found here: https:\/\/support.microsoft.com\/en-us\/help\/4072698\/windows-server-guidance-to-protect-against-the-speculative-executionAntivirusTypical antivirus programs are built on a signature management system, and may not be able to detect the vulnerabilities.\u00a0NCCIC recommends checking with your antivirus vendor to confirm compatibility with Meltdown and Spectre patches.\u00a0Microsoft recommends third-party antivirus vendors add a change to the registry key of the machine running the antivirus software. Without it, that machine will not receive any of the following fixes from Microsoft:Windows UpdateWindows Server Update ServicesSystem Center Configuration Manager\u00a0More information can be found here: https:\/\/support.microsoft.com\/en-us\/help\/4072699\/january-3-2018-windows-security-updates-and-antivirus-software.Vendor LinksThe following table contains links to advisories and patches published in response to the vulnerabilities. This table will be updated as information becomes available.Note: NCCIC strongly recommends:downloading any patches or microcode directly from your vendor&#8217;s websiteusing a test environment to verify each patch before implmentingLink to Vendor InformationDate AddedAmazonJanuary 4, 2018AMDJanuary 4, 2018AndroidJanuary 4, 2018AppleJanuary 4, 2018ARMJanuary 4, 2018CentOSJanuary 4, 2018ChromiumJanuary 4, 2018CiscoJanuary 10, 2018CitrixJanuary 4, 2018DebianJanuary 5, 2018DragonflyBSDJanuary 8, 2018F5January 4, 2018Fedora ProjectJanuary 5, 2018FortinetJanuary 5, 2018HPJanuary 19, 2018GoogleJanuary 4, 2018HuaweiJanuary 4, 2018IBMJanuary 5, 2018IntelJanuary 4, 2018JuniperJanuary 8, 2018LenovoJanuary 4, 2018LinuxJanuary 4, 2018LLVM: variant #2January 8, 2018LLVM: builtin_load_no_speculateJanuary 8, 2018LLVM: llvm.nospeculatedloadJanuary 8, 2018Microsoft AzureJanuary 4, 2018MicrosoftJanuary 4, 2018MozillaJanuary 4, 2018NetAppJanuary 8, 2018NutanixJanuary 10, 2018NVIDIAJanuary 4, 2018OpenSuSEJanuary 4, 2018OracleJanuary 17, 2018QubesJanuary 8, 2018Red HatJanuary 4, 2018SuSEJanuary 4, 2018SynologyJanuary 8, 2018Trend MicroJanuary 4, 2018UbuntuJanuary 17, 2018VMwareJanuary 10, 2018XenJanuary 4, 2018<br \/>\nReferences<br \/>\nGraz University of Technology Meltdown website<br \/>\nGraz University of Technology Spectre website<br \/>\nRogue Data Cache Load: CVE-2017-5754<br \/>\nBounds Check Bypass: CVE-2017-5753<br \/>\nBranch Target Injection: CVE-2017-5715<br \/>\nCERT\/CC\u2019s Vulnerability Note VU#584653<br \/>\nRevision History<br \/>\nJanuary 4, 2018: Initial version<br \/>\nJanuary 5, 2018: Updated vendor information links for Citrix, Mozilla, and IBM in the table and added links to Debian, Fedora Project, and Fortinet<br \/>\nJanuary 8, 2018: Added links to DragonflyBSD, Juniper, LLVM, NetApp, Qubes, and Synology<br \/>\nJanuary 9, 2018: Updated Solution Section<br \/>\nJanuary 10, 2018: Added links to Cisco and Nutanix<br \/>\nJanuary 17, 2018: Added note to Mitigation section and links to Oracle and Ubuntu<br \/>\nJanuary 18, 2018: Updated Description, Impact, and Solution Sections, and added an additional link<br \/>\nJanuary 19, 2018: Added link to HP<br \/>\nJanuary 31, 2018: Provided additional links and updated Description and Mitigation sections<br \/>\nThis product is provided subject to this Notification and this Privacy &amp; Use policy.<\/p>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original release date: January 04, 2018 | Last revised: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[106],"tags":[],"class_list":["post-2537","post","type-post","status-publish","format-standard","hentry","category-alerts-th"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance - humanit managed services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/old.humanit.asia\/ta18-004a\/\" \/>\n<meta property=\"og:locale\" content=\"th_TH\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance - humanit managed services\" \/>\n<meta property=\"og:description\" content=\"Original release date: January 04, 2018 | Last revised: [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/old.humanit.asia\/ta18-004a\/\" \/>\n<meta property=\"og:site_name\" content=\"humanit managed services\" \/>\n<meta property=\"article:published_time\" content=\"2018-03-19T21:30:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-22T08:08:40+00:00\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u0e19\u0e32\u0e17\u0e35\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-004a\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/ta18-004a\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"headline\":\"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance\",\"datePublished\":\"2018-03-19T21:30:05+00:00\",\"dateModified\":\"2019-07-22T08:08:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/ta18-004a\\\/\"},\"wordCount\":773,\"articleSection\":[\"Alerts\"],\"inLanguage\":\"th\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/th\\\/ta18-004a\\\/\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-004a\\\/\",\"name\":\"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance - humanit managed services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\"},\"datePublished\":\"2018-03-19T21:30:05+00:00\",\"dateModified\":\"2019-07-22T08:08:40+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-004a\\\/#breadcrumb\"},\"inLanguage\":\"th\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/old.humanit.asia\\\/ta18-004a\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-004a\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/old.humanit.asia\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\",\"url\":\"https:\\\/\\\/old.old.humanit.asia\\\/\",\"name\":\"humanit managed services\",\"description\":\"making technology easy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/old.old.humanit.asia\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"th\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"caption\":\"Admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance - humanit managed services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/old.humanit.asia\/ta18-004a\/","og_locale":"th_TH","og_type":"article","og_title":"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance - humanit managed services","og_description":"Original release date: January 04, 2018 | Last revised: [&hellip;]","og_url":"https:\/\/old.humanit.asia\/ta18-004a\/","og_site_name":"humanit managed services","article_published_time":"2018-03-19T21:30:05+00:00","article_modified_time":"2019-07-22T08:08:40+00:00","author":"Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Admin","Est. reading time":"4 \u0e19\u0e32\u0e17\u0e35"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/old.humanit.asia\/ta18-004a\/#article","isPartOf":{"@id":"https:\/\/old.humanit.asia\/th\/ta18-004a\/"},"author":{"name":"Admin","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"headline":"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance","datePublished":"2018-03-19T21:30:05+00:00","dateModified":"2019-07-22T08:08:40+00:00","mainEntityOfPage":{"@id":"https:\/\/old.humanit.asia\/th\/ta18-004a\/"},"wordCount":773,"articleSection":["Alerts"],"inLanguage":"th"},{"@type":"WebPage","@id":"https:\/\/old.humanit.asia\/th\/ta18-004a\/","url":"https:\/\/old.humanit.asia\/ta18-004a\/","name":"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance - humanit managed services","isPartOf":{"@id":"https:\/\/old.old.humanit.asia\/#website"},"datePublished":"2018-03-19T21:30:05+00:00","dateModified":"2019-07-22T08:08:40+00:00","author":{"@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"breadcrumb":{"@id":"https:\/\/old.humanit.asia\/ta18-004a\/#breadcrumb"},"inLanguage":"th","potentialAction":[{"@type":"ReadAction","target":["https:\/\/old.humanit.asia\/ta18-004a\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/old.humanit.asia\/ta18-004a\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/old.humanit.asia\/"},{"@type":"ListItem","position":2,"name":"TA18-004A: Meltdown and Spectre Side-Channel Vulnerability Guidance"}]},{"@type":"WebSite","@id":"https:\/\/old.old.humanit.asia\/#website","url":"https:\/\/old.old.humanit.asia\/","name":"humanit managed services","description":"making technology easy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/old.old.humanit.asia\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"th"},{"@type":"Person","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c","name":"Admin","image":{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","caption":"Admin"}}]}},"_links":{"self":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/comments?post=2537"}],"version-history":[{"count":2,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2537\/revisions"}],"predecessor-version":[{"id":2871,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2537\/revisions\/2871"}],"wp:attachment":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media?parent=2537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/categories?post=2537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/tags?post=2537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}