Microsoft updates support documentation to remove methods that disable patches for Downfall vulnerabilities
CTOnews.com Sept. 6, Microsoft recently updated the KB5029778 support documentation to remove the method of disabling Downfall vulnerability patches, saying: "remove the content related to disabling GDS mitigation patches, this option is no longer available."
CTOnews.com reported in August that Intel processors were exposed to Downfall vulnerabilities that affected all modern CPU prior to Intel's 12th-generation Alder Lake CPU, which could steal sensitive information from the system's most secure environment, including user cores, processes, virtual machines, and trusted execution environments.
Downfall vulnerability tracking, numbered CVE-2022-40982, is a transient execution side channel vulnerability (transient execution side-channel) that affects all processors from Skylake to Ice Lake.
In order to fix this vulnerability, Intel released a platform Update (IPU) microcode update of version 23.3. However, this patch will lead to CPU performance loss, according to the preliminary test report released by foreign technology media phoronix, after the deployment of Intel Downfall mitigation patch, the performance loss can be up to 39%.
Related readings:
"Downfall vulnerability exposure: affecting Intel Skylake to Ice Lake family processors to steal sensitive data"
"performance loss up to 39%, Intel Downfall Mitigation Patch Test report released"
"Downfall vulnerability patches affect Intel CPU performance, and Microsoft provides ways to disable patches"