KB5029778 How to manage CVE-2022-40982 "Downfall" CPU vulnerability


KB5029778: How to manage the vulnerability associated with CVE-2022-40982​


Introduction

Microsoft is aware of a new transient execution attack named gather data sampling (GDS) or "Downfall." This vulnerability could be used to infer data from affected CPUs across security boundaries such as user-kernel, processes, virtual machines (VMs), and trusted execution environments.

For more information about this vulnerability, see INTEL-SA-00828 security advisory and CVE-2022-40982.

Mitigate the vulnerability

IMPORTANT The mitigation described in this article is Enabled by default with the option to disable it. We recommend that you mitigate the vulnerability as soon as possible.

Note Intel’s latest products including Alder Lake, Raptor Lake, and Sapphire Rapids, have defense-in-depth measures in place and are not affected by this vulnerability.

To mitigate the vulnerability associated with CVE-2023-40982, install the Intel Platform Update (IPU) 23.3 microcode update. Typically, you need to obtain this update from your original equipment manufacturer (OEM). For a list of OEMs, see System Manufacturers. No further action to mitigate the vulnerability is required.

IMPORTANT We continue to work with Intel on their Gather Data Sample (GDS) Microcode and CPU support. Please refer to Intel for the most up-to-date information on GDS related Microcode and Firmware support from OEMs.

Disable the mitigation

If you do not consider GDS to be part of your threat model, you might choose to turn off (disable) the mitigation in a bare-metal environment.

Note Disabling the mitigation when Hyper-V (Virtualization) is enabled is not in scope of this current implementation.

To disable the GDS mitigation in Windows, you must have the following installed, as appropriate for your environment:
  • On supported Windows 10 and Windows 11 environments, you must have installed the Windows update dated on or after August 22, 2023.
  • On supported Windows Server environments, you must have installed the Windows update dated on or after September 12, 2023.
After the appropriate Windows update is installed, you must set the following feature flag in the registry:

Registry location: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
Value name: FeatureSettingsOverride
Value type: REG_DWORD
Value data: 0x2000000 (hex)

If this registry value does not already exist, run the following command to disable the GDS mitigation:

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 33554432 /f


References

Gather Data Sampling Technical Paper

Threat Analysis Assessment for GDS Paper

Gather Data Sampling Performance Data Analysis Paper

Intel Security Advisory: INTEL-SA-00828

Source:
 
Last edited:

Change log

Change dateChange description
September 1, 2023Removed the content to disable the GDS mitigation as that option is no longer available
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender

Latest Support Threads

Back
Top Bottom