As a user you would leave this setting disabled until you explicitly require it. It's part of malware protection, not even a particularly good one, but one additional hoop that malware authors have to jump through, and the usual cynical approach to security applies: the zebra doesn't have to run faster than the lion, just faster than the slowest other zebra -- if infecting your computer is more effort than infecting a few thousand others, most attackers won't bother. Sign up to join this community.
The best answers are voted up and rise to the top. Stack Overflow for Teams — Collaborate and share knowledge with a private group. Create a free Team What is Teams? Learn more. Why can hardware assisted virtualization be a security issue? Ask Question. Asked 1 year, 10 months ago. Active 3 months ago. Viewed 9k times.
Improve this question. Ruslan 2 2 silver badges 7 7 bronze badges. Isn't the risk not that hypervisor rootkits are possible, but that there might be a yet-unknown vulnerability in a microprocessor's hardware virtualization functionality like Spectre or Meltdown? In which case, keep it enabled until someone claims there's a threat that can be mitigated by disabling it?
TheD It already requires ring 0, so that's not really an issue. Add a comment. Active Oldest Votes. Improve this answer. Surely one can assume they know it is just glitter. Mindwin glitter sells products — Richard Tingle. RichardTingle I think it's more 'tradition' at this point. Windows used to not take advantage of hardware virtualization for any security features, and thus it literally was just yet another way malware could make itself hard to remove for anybody who was not doing any type of virtualization or playing games that use one of the anti-cheat rootkits that use it.
RichardTingle Agreed. They can put a nice checkmark next to "prevents against hypervisor rootkits and virtualization attacks" on their product feature matrix and perhaps their more sensible competitors can't. I don't think that's what the option does, see my answer. Harry Johnston Harry Johnston 1, 9 9 silver badges 14 14 bronze badges.
This makes a lot more sense. I hope OP accepts this answer. It may be worth noting for OP that if you did want to disable the virtualisation capability, thats not for the OS to decide and you would change this in the BIOS.
Question Super giving me worse frames than a ? Started by Small-Change Oct 7, Replies: Graphics Cards. News Comments. Question Gigabyte PC won't boot. Started by Janvdv 53 minutes ago Replies: 3. Question My Ti 4GB had some smoke coming from it. Can it be repaired? Is my motherboard toast? Started by EvanSlowski 51 minutes ago Replies: 1. Latest posts S. Question What causes PC to shut down by itself? Latest: --SID-- A moment ago. Power Supplies.
Latest: Paperdoc A moment ago. Latest: bamitscon 1 minute ago. Wireless Networking. Question Help checking my build changes. Latest: logainofhades 3 minutes ago. Latest: SinaTPB 4 minutes ago. Moderators online. Tom's Hardware is part of Future plc, an international media group and leading digital publisher.
Visit our corporate site. All rights reserved. England and Wales company registration number A hypervisor is software which is able to run a virtual operating system underneath it. The hypervisor, in other words, pretends to be real hardware so the operating system running under it doesn't need to be aware of this fact. You will not improve security by disabling hardware-assisted virtualization. Because it requires such high privileges to use in the first place, any malware that is able to use it is already able to bypass any restrictions you set.
As such, Avast's option to disable this feature provides no additional security, and might actually decrease security by preventing Windows from using it in its HyperV-based sandbox. Choose where you want to search below Search Search the Community. This thread is locked. You can follow the question or vote as helpful, but you cannot reply to this thread. I have the same question Report abuse.
Details required :. Cancel Submit. Reza Ameri Volunteer Moderator.
0コメント