That means as long as you have one of these built-in Microsoft protections enabled the registry key should be set automatically — no further, manual action should be necessary.Big caveat: If you are using third party software that Microsoft offically recognizes as AV, it is important to note that, by default, Windows Defender and Microsoft Security Essentials will turn themselves off.If you are using an AV and haven't received the Windows patch yet, you are advised to wait until your AV vendor either issues an update that sets the registry key for you or specifically recommends that you do so, yourself.

It affects all out-of-order Intel processors released since 1995 with the exception of Itanium and pre-2013 Atoms.

A list of vulnerable ARM processors and mitigations is listed here. Of the two bugs, Meltdown is the easier one to fix, and can largely be addressed with operating system updates.

UPDATE 3/14/18: Microsoft has removed the registry key requirement outlined below for Windows 10 users.

All other Windows versions utilizing third-party antivirus software are still required to have a special registry key set in order to receive updates. This has created a lot of confusion, especially since the response from AV vendors has varied, with some setting the registry key for their customers and others recommending users set it, themselves, manually.

First, you'll need to be running Power Shell with admin privileges and may need to adjust execution policy.

Also, the Install-Module command was introduced to Power Shell in version 5.0.

Restart the server for changes to take add "HKEY_LOCAL_MACHINE\SYSTEM\Current Control Set\Control\Session Manager\Memory Management" /v Feature Settings Override /t REG_DWORD /d 3 /f reg add "HKEY_LOCAL_MACHINE\SYSTEM\Current Control Set\Control\Session Manager\Memory Management" /v Feature Settings Override Mask /t REG_DWORD /d 3 /f Restart the server for the changes to take effect.

(There is no need to change Min Vm Version For Cpu Based Mitigations.) Microsoft also notes that for Hyper-V hosts, live migration between patched and unpatched hosts may fail.

There are two flavors of Spectre — variant 1 (bounds check bypass, CVE-2017-5753) and variant 2 (branch target injection, CVE-2017-5715).

