KB4072698: Windows Server and Azure Stack HCI guidance to protect against silicon-based microarchitectural and speculative execution side-channel vulnerabilities

Wang, Tim 40 Reputation points
2025-04-16T16:37:03.3+00:00

Hi everyone,

I hope someone can help me clarify this. Our security team has started using a new tool called Tenable, and all of a sudden, they started picking up almost all the servers, even server 2022, saying the below 2 keys are either missing or need to be configured to the recommended setting. I am very confused about this. I remembered this was back in 2017 or 2019; it's been a long time. Is it still necessary in 2025? All our servers are fully patched to date.

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d /f

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d  /f

https://support.microsoft.com/en-us/topic/kb4072698-windows-server-and-azure-stack-hci-guidance-to-protect-against-silicon-based-microarchitectural-and-speculative-execution-side-channel-vulnerabilities-2f965763-00e2-8f98-b632-0d96f30c8c8e

Any help is much appreciated

Thanks

Tim

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,653 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.