Microsoft Edge Try Microsoft Edge A fast and secure browser that's designed for Windows 10 Get started

Skip to main content
Microsoft
Microsoft Support
  • Office
  • Windows
  • Surface
  • Xbox
  • Deals
  • Support
      • Windows apps
      • OneDrive
      • Outlook
      • Skype
      • OneNote
      • PCs & tablets
      • Accessories
      • Xbox games
      • PC games
      • Windows digital games
      • Microsoft Azure
      • Microsoft Dynamics 365
      • Microsoft 365
      • Cloud platform
      • Enterprise solutions
      • Data platform
      • .NET
      • Visual Studio
      • Windows Dev Center
      • Docs
      • Free downloads & security
      • Education
      • Gift cards
    • View all
    0
    Sign in
    Microsoft Support

    Surface Guidance to protect against speculative execution side-channel vulnerabilities

    Content provided by Microsoft

    Content provided by Microsoft

    Applies to: Surface Pro 4Surface BookSurface StudioSurface Pro Model 1796Surface LaptopSurface Pro with LTE AdvancedSurface Book 2 - 13 inchSurface Book 2 - 15 inch More


    Introduction


    Customers who use Surface products have to apply both firmware and software updates to protect against speculative execution side-channel vulnerabilities. For more information about the security mitigation, see the following security advisory:

    Microsoft Security Advisory ADV180002

    Summary


    The Surface team is aware of a new publicly disclosed class of vulnerabilities known as “speculative execution side-channel attacks” that affect many modern processors and operating systems, including Intel, AMD, and ARM.

    For additional information about Windows software updates, see the following Knowledge Base article:

    4073119 Windows Client Guidance for IT Pros to protect against speculative execution side-channel vulnerabilities

    Microsoft has not received any information to indicate that these vulnerabilities have been used to attack customers at this time. Microsoft continues to work closely with industry partners, including chipmakers and application vendors, to protect customers. To get all available protections, hardware or firmware updates and software updates are required. This includes microcode and, in some cases, updates to AV software.

    In addition to installing the January 3 Windows Operating System Security Updates, Surface has released UEFI updates via Windows Update and the Download Center for the following devices:

    • Surface Book 2 - (Update history)
    • Surface Book - (Update history)
    • Surface Laptop - (Update history)
    • Surface Studio - (Update history)
    • Surface Pro 4  - (Update history)
    • Surface Pro 3 - (Update History)
    • Surface Pro Model 1796 and Surface Pro with Advanced LTE Model 1807- (Windows Update History)

    These updates are available for devices running Windows 10 Creators Update (build 15063) and Windows 10 Fall Creators Update (build 16299). 

    Note Surface hub has implemented defense in depth strategies. For more information, go to the following topic on the Microsoft website:

    Differences between Surface Hub and Windows 10 Enterprise

    Because of this, we believe that exploits that use these vulnerabilities are significantly reduced on Surface Hub. We will continue to monitor and update Surface Hub as required to address these vulnerabilities and keep the device reliable and secure.

    More Information


    The Surface team is focused on making sure that our users have a secure and reliable experience. We will continue to monitor and update devices as required to address these vulnerabilities.

    References


    • CVE-2017-5753
    • CVE-2017-5715
    • CVE-2017-5754

    Last Updated: 16 Mar 2018
    • Email
    • Print
    Thanks! Your feedback will help us improve the support experience.

    Support

    Support

    • Find downloads
    • Account support
    • Supported products list
    • Microsoft Lifecycle Policy

    Security

    Security

    • Safety & Security Center
    • Download Security Essentials
    • Malicious Software Removal Tool

    Contact us

    Contact us

    • Report a support scam
    • Contact Microsoft Support
    • Privacy questions
    • Locate Microsoft addresses worldwide
    This site in other countries/regions
    Algérie - Français
    Argentina - Español
    Australia - English
    Belgique - Français
    België - Nederlands
    Bolivia - Español
    Bosna i Hercegovina - Hrvatski
    Brasil - Português
    Canada - English
    Canada - Français
    Chile - Español
    Colombia - Español
    Costa Rica - Español
    Crna Gora - Srpski
    Danmark - Dansk
    Deutschland - Deutsch
    Dominican Republic - Español
    Ecuador - Español
    Eesti - Eesti
    El Salvador - Español
    España - Español
    Estados Unidos - Español
    France - Français
    Guatemala - Español
    Hong Kong SAR - English
    Hrvatska - Hrvatski
    India - English
    Indonesia (Bahasa) - Bahasa
    Ireland - English
    Italia - Italiano
    Latvija - Latviešu
    Lietuva - Lietuvių
    Luxembourg - Français
    Magyarország - Magyar
    Malaysia - English
    Maroc - Français
    México - Español
    Nederland - Nederlands
    New Zealand - English
    Norge - Bokmål
    Panamá - Español
    Paraguay - Español
    Perú - Español
    Philippines - English
    Polska - Polski
    Portugal - Português
    Puerto Rico - Español
    România - Română
    Schweiz - Deutsch
    Singapore - English
    Slovenija - Slovenščina
    Slovensko - Slovenčina
    South Africa - English
    Srbija - Srpski
    Suisse - Français
    Suomi - Suomi
    Sverige - Svenska
    Tunisie - Français
    Türkiye - Türkçe
    United Kingdom - English
    United States - English
    Uruguay - Español
    Venezuela - Español
    Việt Nam - Tiếng việt
    Ísland - Íslenska
    Österreich - Deutsch
    Česká Republika - Čeština
    Ελλάδα - Ελληνικά
    България - Български
    Казахстан - Русский
    Россия - Русский
    Україна - Українська
    ישראל - עברית
    الإمارات العربية المتحدة - العربية
    المملكة العربية السعودية - العربية
    مصر - العربية
    भारत - हिंदी
    ไทย - ไทย
    中国 - 简体中文
    台灣 - 繁體中文
    日本 - 日本語
    香港特別行政區 - 繁體中文
    대한민국 - 한국어
    English (Singapore)
    • Terms of use
    • Privacy & cookies
    • Trademarks
    • © Microsoft 2018