Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Meltdown and Spectre

Hi 

 

Meltdown and Spectre are 2 security vulnerabilities on a processor that can allow an attacker to read other process and kernel memory. 

It can be used with Javascript to access memory form the web browser. I can be used in a container or a VM to access other containers/VM memory

Is InterceptX tested against this attacks?

 

Best regards



This thread was automatically locked due to age.
Parents
  • Hi OLIVIERMIOSSEC,

    The reported vulnerability is processsor level flaw that needs to be updated with the Windows securiytupdates.

    The reported security vulnerabilites are addressed in Windows patches that were released ahead of schedule by Microsoft on January 3rd. Sophos is investigating the vulnerability involving a "kernel memory leak" to determine any impact of these vulnerabilities and patches to our products and services.

    For more updates refer Advisory: Kernel memory issue affecting multiple OS (aka F**CKWIT, KAISER, KPTI, Meltdown & Spectre)

    Also check our Nakedsecurity post regarding this Intel CPU flaw needs low-level OS patches.

    Regards,

    Gowtham Mani
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • The other question Sophos users have is in regards to this statement from Microsoft: 

     

    Microsoft's testing revealed a "small number" of antivirus programs are making unsupported calls into Windows kernel memory, which result in blue screen of death (BSOD) errors.

    To avoid causing widespread BSOD problems Microsoft opted to only push its January 3 security updates to devices running antivirus from firms that have confirmed their software is compatible.

    "If you have not been offered the security update, you may be running incompatible antivirus software and you should follow up with your software vendor," the company explains.

    "Microsoft has been working closely with antivirus software partners to ensure all customers receive the January Windows security updates as soon as possible."

     

    Is Sophos stopping the install of this update?

    Thanks.

  • And the link above answers this question. 

Reply Children
No Data