How to Remediate CVE-2017-5754 and CVE-2017-5715 on windows server 2016 having intel processor?

Anonymous
2024-06-10T07:36:37+00:00

My vulnerability scanner found CVE-2017-5754 and CVE-2017-5715 vulnerabilities that are speculative execution side-channel vulnerabilities.

my server is 2016 and running on intel.

I read the following article but didn't understand and confused where to started and then go for additional steps.

https://msrc.microsoft.com/update-guide/en-US/advisory/ADV180002

kindly provide the guidance steps to remediate these vulnerabilities.

Windows Server Devices and deployment Install Windows updates, features, or roles

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes
Accepted answer
  1. Anonymous
    2024-06-12T01:13:21+00:00

    Hello,

    Thank you for posting in Microsoft Community forum.

    Based on the description, I understand your question is related to CVE-2017-5754 and CVE-2017-5715 vulnerabilities.

    Here are the recommend actions for your reference:

    1. Microsoft suggest install the latest windows cumulative updates, the best protection is to keep computers up to date.

     June 11, 2024—KB5039214 (OS Build 14393.7070) - Microsoft Support

    1. Also, as you are using intel, Intel microcode update are also required:

    KB4093836: Summary of Intel Microcode Updates - Microsoft Support

    1. You also need to check below article about registry information to enable mitigations that are not enabled by default:

    KB4072698: Windows Server and Azure Stack HCI guidance to protect against silicon-based microarchitectural and speculative execution side-channel vulnerabilities - Microsoft Support

    Have a nice day. 

    Best Regards,

    Molly

    0 comments No comments

0 additional answers

Sort by: Most helpful