What systems are you seeing this with? You seem to be bouncing back and
forth between servers and clients making it confusing to follow.

 

For servers Microsoft has stated to help protect servers you need:

1.      Apply the Windows OS system update released on Jan. 3, 2018.
2.      Make necessary configuration changes. There are 3 registry entries
to be made. You have to restart the server for the changes to take effect.
3.      Apply a firmware update from your hardware vendor.

 

Expect your servers to take some kind of performance hit.

 

Have you restarted your servers yet?

 

For clients Microsoft has stated to help protect your client machines you
need:

1.      Verify you have a supported antivirus program.
2.      Apply all Windows OS system updates including the Windows security
update released on Jan. 3, 2018.
3.      Apply the firmware update from your hardware vendor, if available.

 

If you only install the Jan. 3, 2018 Windows security update you will not be
fully protected. You also need a firmware update to get all the current
known mitigations. If you haven't applied a firmware update, I would expect
some of the PowerShell entries to be False.

 

Art

 

From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com]
On Behalf Of Michael Leone
Sent: Tuesday, January 9, 2018 1:12 PM
To: ntsysadm@lists.myitforum.com
Subject: Re: [NTSysADM] Are the Meltdown/Spectre reg keys needed for
workstations?

 

On Tue, Jan 9, 2018 at 3:00 PM, Mike <craigslist...@gmail.com
<mailto:craigslist...@gmail.com> > wrote:

You only need the Registry entries on Server versions.

You do need hardware support to protect against CVE-2017-5715.

Run the Get-SpeculationControlSettings PowerShell command to get the
details.
https://gallery.technet.microsoft.com/scriptcenter/Speculation-Control-e36f0
050

 

 

I have run it. It didn't answer my question. If you don't run the registry
entries, some values are false. I take "false" to mean "not as fully
protected as you should be". Which indicates to me that I need the registry
entries, even if it's not a server.

 

Hence my question ...

 

 

Sensitivity: Internal


Reply via email to