Entry type: Product note, Entry ID: 109754953, Entry date: 02/06/2018

Notes on Microsoft Updates 2018-01 (Meltdown and Spectre)

On the 3rd and 08th of January 2018 Microsoft has released updates for the Windows operating systems to close the vulnerabilities, which are grouped under the name Meltdown and Spectre.
There are compatibility issues with these updates, see e.g. the notes in the Windows Server 2012 R2 Update (https://support.microsoft.com/en-us/help/4056895/windows-81-update-kb4056895).
On 17th of January 2018 Microsoft provided the following fixes for affected Windows Updates:

Siemens has no compatibility issues with the corrected KBs except for the three products listed below. For the exceptions, please note the following product releases:

Microsoft reports possible performance issues depending on the hardware, operating system, and applications used. Siemens is currently unable to make any statements about performance issues for SIMATIC Software. Siemens continues to test the effects of these updates on the SIMATIC software.

Therefore, prior to rolling out the updates to the production environment, Siemens recommends installing or testing all updates in a test environment.

As new information becomes available, this post will be updated.
Furthermore, Siemens recommends the usage and implementation of the Defense-in-Depth concept. Further information can be found here: https://www.siemens.com/industrialsecurity.