This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos compatibility for MS KB405689X patches to address Meltdown vulnerability (and others)

I have read through articles https://community.sophos.com/kb/en-us/128053 and https://community.sophos.com/kb/en-us/128060 but I'm still not clear on which version of Endpoint is compatible with the MS KB405689X Meltdown patches...

Our clients currently have Endpoint Security and Control version 10.7

Sophos Anti-Virus 10.7.2.49
On-access status Enabled
Detection engine 3.69.2
Detection data 5.46
Virus data date 28/11/2017

Also:

Sophos AutoUpdate 5.7.533
Last checked for updates 08/01/2018 15:56:43
Update status Success

Our definitions do include the necessary IDE files:

zbot-lvw.ide
netwi-md.ide
age-axyx.ide
pdfu-dwf.ide

I noticed we don't yet have the required registry entry "HKEY_LOCAL_MACHINE" Subkey="SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat" Value="cadca5fe-87d3-4b96-b7fb-a231484277cc" Type="REG_DWORD”
Data="0x00000000”

... so I have manually added this to the registry of a test Win7 machine which then allowed deployment of patches KB4056894 and KB4056897

The machine doesn't appear to have any issues, but before rolling the reg value out to the estate in order to deploy the MS patches, is anybody able to confirm officially that the Sophos client version (shown above) is actually compatible with these MS patches?

Thanks



This thread was automatically locked due to age.
Parents
  • Exact same situation here.  Client versions are the same, our Enterprise Console groups/policies only subscribe and point to "Recommended".  Reg key is not getting set as the Sophos KB claims it should have been starting on the 5th.

     

    EDIT: Seems like nothing may be wrong as of now; The updates are being staggered between Jan. 5 and Jan. 9, it seems: https://community.sophos.com/kb/en-us/128060

  • Has anyone got the update? Been waiting since Friday, need it to send out the update to our test machines.

Reply Children
No Data