cancel
Showing results for 
Search instead for 
Did you mean: 
Birraque
Token Ring
Posts: 171
Location: BR
6,093 Views

Yoga 2 Pro new Firmware to address Spectre and Meltdown security risks

Microsoft released a rare out-of-band security update to supported many versions of Windows. The software update is part of a number of fixes that will protect against a newly-discovered processor bug in Intel, AMD, and ARM chipsets. ADV180002 | Guidance to mitigate speculative execution side-channel vulnerabilities

Dubbed “Meltdown” and “Spectre,” the flaws affect nearly every device made in the past 20 years, and could allow attackers to use JavaScript code running in a browser to access memory in the attacker’s process. That memory content could contain key strokes, passwords, and other valuable information. More Info

For consumers, to keep Windows up to date is the first step but is mandatory to install applicable Firmware (BIOS) update provided by OEM device manufacturer.

 

1) Microsoft has released the following patches for Windows 10:
KB4056892 (OS Build 16299.192)
KB4056891 (OS Build 15063.850)
KB4056890 (OS Build 14393.2007)
KB4056888 (OS Build 10586.1356)
KB4056893 (OS Build 10240.17738)
(*) Verifying that protections are enabled, you are protected if all lines have the "True" value.

 

Verification using the PowerShell, Lenovo Yoga 2 Pro (20266 / 80AY), Patches InstalledVerification using the PowerShell, Lenovo Yoga 2 Pro (20266 / 80AY), Patches Installed

2) Then I would like to know when Lenovo Yoga 2 Pro (20266 / 80AY) is going to receive a microcode fix (Firmware Update) to address Spectre and Meltdown security risks?

Currently it isn't even listed under Lenovo Security Advisory LEN-18282

Please support your costumers with a proper Firmware.

 

Best Regards,

Who Me Too'd this topic