Data: CASIE
Negative Trigger
,
the
researcher
wrote
today
in
a
tweet
.
Microsoft
quietly
fixed
Vulnerability-related.PatchVulnerability
the
issue
on
Windows
10
Redstone
4
(
v1803
)
,
also
known
as
the
April
2018
Update
,
released
Vulnerability-related.PatchVulnerability
on
Monday
.
``
Welp
,
it
turns out
Vulnerability-related.PatchVulnerability
the
Meltdown
patches
for
Windows
10
had
a
fatal
flaw
:
calling
NtCallEnclave
returned
back
to
user
space
with
the
full
kernel
page
table
directory
,
completely
undermining
the
mitigation
,
''
Ionescu
wrote
.
Microsoft
issued
Vulnerability-related.PatchVulnerability
today
an
security
update
,
but
it
was
n't
to
backport
the
``
fixed
''
Meltdown
patches
for
older
Windows
10
versions
.
Instead
,
the
emergency
update
fixed
Vulnerability-related.PatchVulnerability
a
vulnerability
in
the
Windows
Host
Compute
Service
Shim
(
hcsshim
)
library
(
CVE-2018-8115
)
that
allows
an
attacker
to
remotely
execute
code
on
vulnerable
systems
.
Microsoft
classified
Vulnerability-related.DiscoverVulnerability
CVE-2018-8115
as
a
``
critical
''
issues
.
A
patched
hcsshim
file
is available
Vulnerability-related.PatchVulnerability
for
download
from
GitHub
.
``
We
are
aware
and
are
working
to
provide
Vulnerability-related.PatchVulnerability
customers
with
an
update
,
''
a
Microsoft
spokesperson
told
Bleeping
Computer
today
in
an
email
.
It
may
be
that
if
Microsoft
does
n't
bundle
these
fixes
in
an
out-of-band
update
,
they
will
most
likely
arrive
Vulnerability-related.PatchVulnerability
in
Microsoft
's
May
2018
Patch
Tuesday
,
but
this
is
only
our
speculation
.
Microsoft
released
Vulnerability-related.PatchVulnerability
its
Meltdown
and
Spectre
patches
on
January
4
,
a
day
after
security
researchers
disclosed
Vulnerability-related.DiscoverVulnerability
the
two
flaws
,
vulnerabilities
that
allow
attackers
to
retrieve
data
from
protected
areas
of
modern
CPUs
.
The
Redmond-based
OS
maker
has
had
a
hard
time
patching
Vulnerability-related.PatchVulnerability
the
two
flaws
,
and
the
company
recently
issued
Vulnerability-related.PatchVulnerability
additional
security
updates
to
fix
Vulnerability-related.PatchVulnerability
the
original
Spectre
mitigations
,
and
also
deliver
Vulnerability-related.PatchVulnerability
Intel
CPU
microcode
updates
,
as
a
favor
to
Intel
.