KB4072698: Windows Server and Azure Stack HCI guidance to protect against silicon-based microarchitectural and speculative execution side-channel vulnerabilities
Hi everyone,
I hope someone can help me clarify this. Our security team has started using a new tool called Tenable, and all of a sudden, they started picking up almost all the servers, even server 2022, saying the below 2 keys are either missing or need to be configured to the recommended setting. I am very confused about this. I remembered this was back in 2017 or 2019; it's been a long time. Is it still necessary in 2025? All our servers are fully patched to date.
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d /f
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d /f
Any help is much appreciated
Thanks
Tim