Recommended Free Tools
On an affected Intel PC, the supported fix is an original-equipment-manufacturer (OEM) BIOS or firmware update containing Intel Platform Update (IPU) 23.3 microcode. Microsoft says its Windows mitigation for Downfall—also called Gather Data Sampling (GDS), CVE-2022-40982—is enabled by default and cannot be disabled through the documented setting. After installing the applicable OEM firmware, Microsoft says no additional mitigation action is required.
First identify the exact processor and computer manufacturer. Windows 10 or Windows 11 alone does not establish whether a system is affected.
What Downfall is
Downfall is Intel’s name for Gather Data Sampling (GDS), a transient-execution side-channel vulnerability identified as CVE-2022-40982. On certain Intel processors, gather instructions can transiently expose stale data from vector registers. An attacker must already be able to execute code locally; the leaked data is associated with the same physical CPU core and is not selected directly by the attacker.
Depending on the system, data could have originated across security boundaries such as the operating-system kernel, another process, a virtual machine, or an Intel SGX enclave. Intel rates CVE-2022-40982 Medium with a CVSS base score of 6.5. That rating describes the vulnerability, not the actual risk of a particular PC or workload. See Intel’s advisory and Intel’s technical documentation.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Who needs to act
The issue affects certain Intel processor models, not every Intel CPU. Microsoft specifically identifies Alder Lake, Raptor Lake, and Sapphire Rapids products as having defense-in-depth protections and not being affected. For other processors, use the exact model in Intel’s affected-processor information and the support page for the computer or motherboard manufacturer. Do not infer status from a marketing family name or from the Windows edition.
| Check | What it tells you |
|---|---|
| Exact Intel processor model | Whether Intel lists the CPU as affected or protected |
| Computer or motherboard maker | Where the applicable BIOS or firmware package is published |
| Windows 10 or Windows 11 support status | Whether Microsoft’s documented mitigation applies to that supported Windows installation |
How to mitigate Downfall on a Windows PC
-
Identify the processor and manufacturer
In Windows, open Settings > System > About and record the processor model and device model. You can also press Windows key + R, enter
msinfo32, and note Processor, System Manufacturer, and System Model.Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
-
Check Intel’s affected-processor guidance
Compare the complete processor model—not just “Core,” “Xeon,” or a generation label—with Intel’s CVE-2022-40982 advisory and GDS technical documentation.
-
Find the OEM firmware update
Open the support page for the PC maker (or motherboard maker for a custom system), search by the exact model or serial number, and read the BIOS or UEFI release notes. Intel recommends obtaining the latest system-manufacturer firmware for affected processors; the package should contain the applicable Intel IPU 23.3 microcode.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
-
Install the firmware safely
Follow the manufacturer’s instructions exactly. Connect AC power on a laptop, avoid interrupting the update, and use the vendor’s recovery procedure if its updater reports a failure. Firmware delivery and naming differ by OEM, so there is no universal Intel download that replaces the manufacturer’s package.
-
Allow Windows’ mitigation to remain enabled
Microsoft states in KB5029778 that the mitigation is enabled by default with no option to disable it. Once the applicable microcode is installed, Microsoft says no further mitigation action is required.
Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Do not apply old registry advice
Downfall is not mitigated by copying registry settings intended for unrelated speculative-execution vulnerabilities. Microsoft’s current guidance removed its earlier mitigation-disable instructions on September 1, 2023, and clarified the scope for supported Windows versions on affected CPUs on September 12, 2023. Leave the documented Windows mitigation enabled and use the OEM firmware path instead.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Performance and threat context
Intel says the microcode mitigation blocks transient gather results when the patch is loaded. Most workloads are expected to see minimal performance impact, but Intel’s technical documentation describes possible impacts of up to 50% for specific workloads. That upper figure applies to particular CPU-intensive, vectorization-heavy workloads; it is not an expected result for ordinary Windows use.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
In an August 8, 2023 advisory, Intel said it was not aware of exploitation outside a controlled laboratory environment. That was Intel’s assessment at that time, not a guarantee that exploitation is impossible or a current independent threat-intelligence determination.
When an update is unavailable
If the OEM provides no BIOS or firmware update, verify the processor model and contact the manufacturer’s support channel. Keep Windows fully updated, restrict untrusted local code execution, and treat the absence of a firmware package as an unresolved vendor-support limitation rather than evidence that the CPU is unaffected. Do not substitute antivirus software, system cleaners, or replacement utilities for the microcode update.
Bottom line for Windows 10 and Windows 11 users
Identify the exact Intel CPU, verify its status with Intel, and install the computer maker’s firmware containing IPU 23.3 when the processor is affected. Microsoft’s Downfall mitigation is already enabled by default and has no documented disable switch; after the OEM microcode update, Microsoft says there is nothing else to configure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →

