Important note about Windows Update KB4056892

Date posted: 2018-01-05
Last updated: 2026-10-04

Microsoft's January 2018 Meltdown and Spectre updates, like KB4056892, were only offered when the QualityCompat registry key was set by your anti-virus software.

There is another VERY IMPORTANT THING with Microsoft Meltdown patches like update KB4056892: customers will not receive these security updates, and will not be protected from security vulnerabilities, unless their anti-virus software vendor sets a specific registry key.

The January 2018 Meltdown and Spectre security updates were only offered to systems with the QualityCompat registry value cadca5fe-87d3-4b96-b7fb-a231484277cc set, normally by a compatible anti-virus product. Verify it with PowerShell, create it yourself if needed, and on Windows Server explicitly enable the mitigations.

I originally wrote this post in January 2018, right after Meltdown and Spectre were disclosed. The QualityCompat registry key is no longer required since March 13th, 2018, and the Windows 10 versions mentioned below are long out of support. Keep your systems up to date with the latest cumulative updates.

The QualityCompat registry key

Contact your anti-virus (AV) vendor to confirm that their software is compatible and has set the following registry key on the machine:

Key="HKEY_LOCAL_MACHINE"
Subkey="SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat"
Value Name="cadca5fe-87d3-4b96-b7fb-a231484277cc"
Type="REG_DWORD"
Data="0x00000000"

Verify whether this QualityCompat registry key is present using PowerShell:

PS C:\Users\jan> (Get-ItemProperty "HKLM:SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat")

You can create the registry DWORD value yourself if it's not present:

D:\Users\JanR>type v:\dev\qualitycompat.reg
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat]
"cadca5fe-87d3-4b96-b7fb-a231484277cc"=dword:00000000
D:\Users\JanR>reg import v:\dev\qualitycompat.reg
The operation completed successfully.

This registry key value is no longer required since March 13th, 2018.

Why Microsoft required this registry key

Microsoft published additional information regarding the Windows security updates released in January 2018. They identified a compatibility issue with a small number of anti-virus products:

The compatibility issue is caused when anti-virus applications make unsupported calls into Windows kernel memory.

These calls could cause stop errors (blue screens) that leave a device unable to boot. To prevent that, Microsoft only offered the security updates released on January 3, 2018 to devices running anti-virus software from partners who confirmed their software was compatible. If you were not offered the update, you might be running incompatible anti-virus software and should follow up with your vendor.

Install the Meltdown and Spectre updates

Make sure you install KB4056890 and KB4056892 to patch your systems for Meltdown and Spectre!

Windows Server admins must enable the kernel-user space splitting feature once it is installed; it's not on by default.

CNET explained in How to protect your PC against the Intel chip flaw how Windows 10 users get this out-of-band emergency patch: it should be offered through Settings > Update & security > Windows Update. If you are running Windows 10 version 1709 (Fall Creators Update), the patch you need is the Security Update for Windows KB4056892. For older versions of Windows 10, the patch numbers are:

  • Windows 10 version 1703 (Creators Update): KB4056891
  • Windows 10 version 1607 (Anniversary Update): KB4056890
  • Windows 10 version 1511 (November Update): KB4056888
  • Windows 10 version 1507 (Initial Release): KB4056893

If you have yet to receive the patch via Windows Update, you can manually install it from the Microsoft Update Catalog. Odds are you are running a 64-bit version of Windows, so you'll want to install the file for x64-based systems. For the Fall Creators Update that is "2018-01 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4056892)".

Want to script this? Here is how to install Windows Updates using PowerShell.

Meltdown and Spectre

What are CVE-2017-5753 and CVE-2017-5715? CVE-2017-5753 and CVE-2017-5715 are the official references to Spectre. CVE is the Standard for Information Security Vulnerability Names maintained by MITRE.

What is CVE-2017-5754? CVE-2017-5754 is the official reference to Meltdown.

See meltdownattack.com for more information.

I write these posts in my spare time, based on real problems from my day job as a sysadmin. If this one saved you some debugging time, a small donation is much appreciated. Thanks! 🙏

Leave a Comment