Endpoint Protection

 View Only
  • 1.  SEP KAISER - KTPI / MELTDOWN Compatibility (Windows)

    Posted Jan 03, 2018 07:37 PM

    Hi Symantec,

    Microsoft has just released guidance on the KAISER - KTPI vulnerabilities regarding processors (widely reported as an Intel bug) (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754).

    Microsoft's guidance states to check with your AV vendor before the upcoming patch tuesday on January 9th, as the patch will not apply unless the AV vendor has set the following registry key to indicate compatibility with the update:

    Key="HKEY_LOCAL_MACHINE"Subkey="SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat"
    Value Name="cadca5fe-87d3-4b96-b7fb-a231484277cc"
    Type="REG_DWORD”
    Data="0x00000000”

    I have checked endpoints running the latest SEP 14 RU1 and can confirm on Windows 10 this registry key is not present.

    A few questions:

    Is Symantec going to release guidance on this before the Patch Tuesday date?
    Is SEP compatible with the new Kernel patches?

    I don't see at this point how Symantec is going to push out the registry key update to customers on older versions, so it may be that this key will need to be set manually if people want to apply the security update.

    Microsoft information: https://support.microsoft.com/en-us/help/4056892/windows-10-update-kb4056892 (only Windows 10 at the time of posting).

    I'll follow this up with professional support as well.



  • 2.  RE: SEP KAISER - KTPI / MELTDOWN Compatibility (Windows)

    Posted Jan 04, 2018 11:41 AM

    New KB article just went up from Symantec:

    http://www.symantec.com/docs/TECH248545



  • 3.  RE: SEP KAISER - KTPI / MELTDOWN Compatibility (Windows)

    Posted Jan 04, 2018 04:12 PM

    I second this - need clarification for older builds of SEP 12.



  • 4.  RE: SEP KAISER - KTPI / MELTDOWN Compatibility (Windows)

    Trusted Advisor
    Posted Jan 05, 2018 03:04 AM

    Anthony Greer -  for SEP v12.1 - the advice from Symantec was "simply allowing SEP 12.1 clients to receive Virus and Spyware definitions dated January 4th, 2018 rev 1 or newer will get them the necessary ERASER update"

    https://www.symantec.com/connect/forums/latest-win10-update-corrupts-sep14#comment-11949711

    For SEP v11 - this is unsupported and no longer receive Defs anyway so you will need to upgrade to v14.



  • 5.  RE: SEP KAISER - KTPI / MELTDOWN Compatibility (Windows)

    Posted Jan 05, 2018 04:20 AM

    Hello all,

    Just adding a link to a new Symantec Security Response blog post that may be of interest:

    Meltdown and Spectre: Chip Vulnerabilities Could Facilitate Memory Leaks
    https://www.symantec.com/blogs/threat-intelligence/meltdown-spectre-cpu-bugs