Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Meltdown and Spectre

Hi 

 

Meltdown and Spectre are 2 security vulnerabilities on a processor that can allow an attacker to read other process and kernel memory. 

It can be used with Javascript to access memory form the web browser. I can be used in a container or a VM to access other containers/VM memory

Is InterceptX tested against this attacks?

 

Best regards



This thread was automatically locked due to age.
Parents Reply Children
  • I believe what most Sophos customers would like to know is whether Sophos can detect malicious code designed to take advantage of these new vulnerabilities. 

    In other words, are Sophos customers with properly installed, updated and running Sophos Endpoint Agent protected against Meltdown/Spectre?

  • The other question Sophos users have is in regards to this statement from Microsoft: 

     

    Microsoft's testing revealed a "small number" of antivirus programs are making unsupported calls into Windows kernel memory, which result in blue screen of death (BSOD) errors.

    To avoid causing widespread BSOD problems Microsoft opted to only push its January 3 security updates to devices running antivirus from firms that have confirmed their software is compatible.

    "If you have not been offered the security update, you may be running incompatible antivirus software and you should follow up with your software vendor," the company explains.

    "Microsoft has been working closely with antivirus software partners to ensure all customers receive the January Windows security updates as soon as possible."

     

    Is Sophos stopping the install of this update?

    Thanks.

  • And the link above answers this question. 

  • That doesn't reply to my question 

    I thought that IntercepX was an anti-exploit and that it can deal NOT with the vulnerabilities but with the attack that can use these vulnerabilities.

    And if I understand well, apply the MS Patch may trigger a BSOD if the AV is not up to date and if a key was added in the registry (QualityCompat)