Microsoft has released new Intel microcode updates for older versions of Windows 10 to address the recently disclosed Microarchitectural Data Sampling (MDS) attacks that affect Intel CPUs.
Microsoft has already released software updates to address the four MDS speculative execution side-channel vulnerabilities, known as Zombieload, RIDL, and Fallout, and the company has now released Intel microcode updates that are required to be fully protected.
The new Intel microcode updates from Microsoft, spotted by BleepingComputer, are for some older versions of Windows 10. The updates are available from the Microsoft update Catalog website.
KB4494175 applies to Windows Server 2016, Windows 10, version 1607; KB4494452 applies to Windows 10, version 1709; KB4494453 applies to Windows 10, version 1703; and KB4494454 applies to Windows 10 RTM.
An attacker could use the MDS flaws to retrieve data from inside Intel CPUs in processes to which the attacker's code should not have access.
According to Microsoft, an MDS attack on computers in the cloud could allow one virtual machine to improperly access information from another.
While major cloud providers have already applied mitigations for the MDS attacks, it's expected to take much longer for consumer PCs to receive the full fix.
Microsoft lists dozens of Intel CPUs for which the microcode update is available, ranging from Ivy Bridge CPUs to Intel's latest 9th generation Core processors.
Microsoft notes that these updates are standalone updates targeted to the respective versions of Windows 10.
"This update also includes Intel microcode updates that were already released for these operating systems at the time of release to manufacturing (RTM)," it adds.
It also urges users and admins to hold off applying these updates until they check with their device manufacturer and Intel websites to see what's recommended regarding the microcode.
More on MDS and Windows 10 security
- How to test MDS (Zombieload) patch status on Windows systems
- Fending off Zombieload attacks will crush your performance
- Windows 10 security: Are ads in Microsoft's own apps pushing fake malware alerts?
- How to fully protect your Mac against Zombieland bug, and how badly it affects performance
- Patch status for the new MDS attacks against Intel CPUs
- Linux vs. Zombieload
- Intel CPUs impacted by new Zombieload side-channel attack
- KRACK attack: Here's how companies are responding CNET
- Top 10 app vulnerabilities: Unpatched plugins and extensions dominate TechRepublic