Microsoft releases new patches for Win10 / Win11 to fix MMIO stale data vulnerabilities in Intel processors
CTOnews.com March 4, Intel reported on June 14, 2022 that there was a MMIO stale data vulnerability in Intel's 6th-generation Core processors and Xeon E processors. Microsoft today released a new set of security patches to fix the above security vulnerabilities in Win10 and Win11 systems.
An attacker who successfully exploits these vulnerabilities may read privileged data across trust boundaries. In a shared resource environment, such as in some cloud service configurations, these vulnerabilities may allow one virtual machine to incorrectly access information in another virtual machine. On stand-alone systems in non-browsing scenarios, attackers must access the system or be able to run specially designed applications on the target system before they can exploit these vulnerabilities.
These vulnerabilities include:
CVE-2022-21123-shared buffer data read (SBDR)
CVE-2022-21125-shared buffer data sampling (SBDS)
CVE-2022-21127-Special register buffer data sampling update (SRBDS update)
CVE-2022-21166-device register partial write (DRPW)
CTOnews.com comes with an update released by Microsoft today as follows:
KB5019180-Windows 10, version 20H2, 21H2, and 22H2
KB5019177-Windows 11, version 21H2
KB5019178-Windows 11, version 22H2
KB5019182-Windows Server 2016
KB5019181-Windows Server 2019
KB5019106-Windows Server 2022