Windows 10 Meltdown Patch Has 'Fatal Flaw,' Update Now

Microsoft may have patched Windows 10 for Meltdown, but a security researcher claims that the patch had a "fatal flaw" that undermines the purported protection. The only way to get a true fix is to update to the Windows 10 April 2018 Update, which was released earlier this week. Bleeping Computer first reported the news.

Alex Ionescu of Crowdstrike wrote on wrote on Twitter that "#Meltdown patches for Windows 10 had a fatal flaw: calling NtCallEnclave returned back to user space with the full kernel page table directory, completely undermining the mitigation." 

The layman's explanation there is that the patch still allowed access to the kernel, therefore undermining the use of having a patch at all. In other words, you're still vulnerable to Meltdown. This requires local code execution privileges and occurs only on Windows 10 Build 1709, the Fall Creators Update. If you've been updating your computer over Windows Update, that's very likely the version you have right now.

MORE: Meltdown and Spectre: How to Protect Your PC, Mac and Phone

Also, wanted to share this additional information as fyi -- The described technique requires local code execution privileges and is limited to Windows build 1709.

"We are aware and are working to provide customers with an update," a Microsoft spokesperson told Laptop Mag.

According to Bleeping Computer, the issue was fixed in the April 2018 major Windows 10 update that was released on Monday. This puts users in a bit of a predicament, as many like to wait until the kinks are worked out in new releases.

Additionally, you still have to manually download the new update, as it is not rolling out automatically just yet. Even then, it could take a long time for the April 2018 update to finally reach your PC.

Ionescu's point that there is "no backport" suggests that Microsoft has yet to bring the fix to older versions of Windows 10. Hopefully, we'll see a new fix on May 8, this month's Patch Tuesday.

Meltdown and another vulnerability, Spectre, were disclosed by Google's Project Zero and other researchers back in January. Meltdown affects almost every Intel processor going back to the mid-1990s, and Spectre affects many ARM and AMD processors as well. You can't currently buy a laptop or desktop without at least one of these vulnerabilities, though mitigations have come through via both operating-system and chip-firmware patches.

Image credit: Natascha Eidl/Public domain

This article originally appeared on Laptop Mag.

TOPICS
Andrew E. Freedman

Andrew E. Freedman is an editor at Tom's Hardware focusing on laptops, desktops and gaming as well as keeping up with the latest news. He holds a M.S. in Journalism (Digital Media) from Columbia University. A lover of all things gaming and tech, his previous work has shown up in Kotaku, PCMag, Complex, Tom's Guide and Laptop Mag among others.

Latest in Windows Operating Systems
Microsoft Office is finally as it should have been on iPad
Microsoft tests free Word, PowerPoint and Excel apps for Windows — expect a lot of ads
laptop anger
Latest Windows 11 update reportedly breaking major parts of the operating system
Windows 10 logo
Windows 10 end of life set for this year — everything you need to know to get ready
Windows 11 logo on a laptop screen
I reviewed Windows 11, and these are the 5 new features I'm most excited about for 2025
A Windows 11 laptop, demonstrating how to run Android apps on Windows 11
How to remove the Windows 11 news and weather widget
Man typing on Windows 11 laptop
Microsoft confirms major Windows 11 and Windows 10 audio bug is cutting sound on PCs
Latest in News
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy