ASUS Update on Speculative Execution and Indirect Branch Prediction Side Channel Analysis Method

    ASUS is aware of recent security research disclosing software analysis methods known as Meltdown and Spectre that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that are operating as designed. ASUS is working closely with platform owners and OS partners to provide solutions.


    Symptom Description

    Malicious code utilizing a new method of side channel analysis and running locally on a normally operating platform has the potential to allow the inference of data values from memory. The use of this method might facilitate access to unauthorized information to an attacker with local user access.
    The following Intel-based platforms are impacted by this issue, and the list may be modified based on the updates from platform owners at a later time.

    • 2nd generation Intel®Core™ processors
    • 3rd generation Intel®Core™ processors
    • 4th generation Intel®Core™ processors
    • 5th generation Intel®Core™ processors
    • 6th generation Intel®Core™ processors
    • 7th generation Intel®Core™ processors
    • 8th generation Intel®Core™ processors
    • Intel®Atom™ Processor Z Series
    • Intel®Celeron®Processor J Series
    • Intel®Celeron®Processor N Series
    • Intel®Pentium®Processor J Series
    • Intel®Pentium®Processor N Series

    For more details, please visit Intel Security Center.


    Important Notice: ASUS BIOS Update FAQ

    (1)How can I find “System Model Name”?
    https://www.asus.com/support/FAQ/1030673

    (2)How do I update my computer’s BIOS?
    https://www.asus.com/support/FAQ/1008859

    In order to successfully install the latest software solutions for overall protection, please keep your computer plugged in and do not turn off your computer during the BIOS update process.


    ASUS Solutions

    To enhance resiliency to the side channel analysis method, ASUS will provide a solution in a forthcoming BIOS update. Together with the latest Windows OS Hot Fix update, your computer will be well protected.
    Although applying the BIOS update and OS Hot Fix will mitigate the risk of the side channel analysis method, computer performance might be impacted. However, any performance impacts are workload-dependent and may vary by hardware generation and implementation by the chip manufacturer. For most users, the performance impact should not be significant.

    (1)ASUS BIOS Update

    Please find our first wave model list below and download the appropriate BIOS update from the ASUS Support Site:
    https://www.asus.com/support/#.

    More details will be added to this document as they become available.

    Laptops:

    System Model Name
    Target Release Date
    B9440UA Jan/E, 2018
    P2440UA Jan/E, 2018
    P2440UQ Jan/E, 2018
    P2540UV Jan/E, 2018
    UX370UA Jan/E, 2018
    UX461UA Jan/E, 2018
    UX461UN Jan/E, 2018
    UX561UA Jan/E, 2018
    UX561UD Jan/E, 2018
    UX561UN Jan/E, 2018
    X510UA Jan/E, 2018
    X510UAR Jan/E, 2018
    X510UF Jan/E, 2018
    X510UN Jan/E, 2018
    X510UNR Jan/E, 2018
    X510UQ Jan/E, 2018
    X510UQR Jan/E, 2018
    X510UR Jan/E, 2018
    X510URR Jan/E, 2018
    X580VD Jan/E, 2018
    X580VN Jan/E, 2018

    Commercial Desktop:

    System Model Name
    Target Release Date
    D630MT Jan/E, 2018
    D630SF Jan/E, 2018
    D631MT Jan/E, 2018
    D830MT Jan/E, 2018
    D830SF Jan/E, 2018
    D831MT Jan/E, 2018

    Mini PCs:

    Segment
    Model name
    Target Release Date
    GR series GR8 II Jan/E, 2018
    EBOX Series E510 Jan/E, 2018
    E810 Jan/E, 2018
    E420 Jan/E, 2018
    E520 Jan/E, 2018
    VC series VC65R Jan/E, 2018
    VC65 Jan/E, 2018
    VC66R Jan/E, 2018
    VC66D Jan/E, 2018
    VC66 Jan/E, 2018
    VC68V Jan/E, 2018
    VC68R Jan/E, 2018
    VM series VM45 Jan/E, 2018
    VM65 Jan/E, 2018
    VM65N Jan/E, 2018
    VM65N Jan/E, 2018
    VM65 Jan/E, 2018
    UN series UN65 Jan/E, 2018
    UN65H Jan/E, 2018
    UN65U Jan/E, 2018
    UN68U Jan/E, 2018

    (2)Windows OS Hot Fix Update

    The OS Build version and KB number listed below are the latest version released from Microsoft to solve this issue. Please make sure your computer has been updated.

    OS Build
    OS Security updates
    Internet Explorer 11
    Microsoft Edge
    Windows 7: OS build 6.1.7600.xx
    Please upgrade to Win 7 with SP1, then using Win 7 SP1 security updates
    Windows 7 (SP1): OS build 6.1.7601.xx
    N/A
    Windows 8: OS build 6.2.9200.xx
    Please upgrade Win 8.1, then using Win 8.1 security updates
    Windows 8.1: OS build 6.3.9200.xx
    N/A
    Windows 8.1 (SP1): OS build 6.3.9600.xx
    N/A
    Win10 TH1 : Version 1507, OS build 10240.xx
    Please upgrade your OS to TH2 above, then using their security updates
    Win10 TH2 : Version 1511, OS build 10586.xx
    Win10 RS1 : Version 1607, OS build 14393.xx
    Win10 RS2 : Version 1703, OS build 15063.xx
    Win10 RS3 : Version 1709, OS build 16299.xx

    Visit the Microsoft Security TechCenter (https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002) to learn more about the security updates.


    How to update OS and check KB number?

    Step 1: Please Update to the Latest Version of Windows


    Step 2: Please Update to the Latest Version of Windows

    Type “winver” in the Search Bar and then press Enter to view your Windows version and OS Build information.


    Step 3: Check the KB Number of Your Latest Windows Update

    Type “Control Panel” in the Search Bar, then select Programs > Uninstall a program > View installed updates.


    A list of updates will be displayed. The KB number for each update is shown in parentheses. Verify the KB number for the latest Windows update.


    FOR THE MOST UP TO DATE INFORMATION, PLEASE REMAIN CURRENT WITH UPDATES AND ADVISORIES FROM ASUS REGARDING YOUR EQUIPMENT AND SOFTWARE. THE INFORMATION PROVIDED IN THIS ADVISORY IS PROVIDED ON AS “AS IS” BASIS WITHOUT ANY WARRANTY OR GUARANTEE OF ANY KIND. ASUS RESERVES THE RIGHT TO CHANGE OR UPDATE THIS ADVISORY AT ANY TIME WITHOUT NOTICE.