-
Microsoft offers more Spectre v2 microcode updates, KB 4090007, KB 4091663, KB 4091664
Yesterday, I posted a note about two new Spectre v2 patches, KB 4078407 and KB 4091666.
The first is a Win10-only fix that has to be combined with a microcode change from your hardware manufacturer in order to accomplish anything. As @abbodi86 notes:
KB4078407 is not a patch, it’s just an executable that enables the Spectre mitigation protection by changing two registry entries
The second is a microcode-only, Intel-only, Win10 1507-only patch that changes the microcode for a large number of Intel processors.
This morning, Günter Born notes on Borncity that there are now four of these microcode patches:
- KB4090007 for Win10 1709/”Server 2016 version 1709″
- KB4091663 for Win10 1703
- KB4091664 for Win10 1607/Server 2016
In addition to the one I described yesterday, KB4091666 for Win10 1507.
None of them are available through Windows Update. You have to manually dig into the Update Catalog to get them.
As noted (voluminously) there are no known exploits as yet for Meltdown, Spectre v1 or Spectre v2. You might want to tuck these away in case we ever see a reason to use them.