AMD processors suffer a unique vulnerability, but we don't know which ones
To date, the vulnerabilities that have appeared mainly affect Intel processors. It has now been made known by AMD that select processors and APUs released between 2016 and 2019 suffers a vulnerability. This vulnerability is called SMM Callout Privilege Escalation Vulnerability and has been labeled CVE-2020-12890. That we know of is the first to date that only affects AMD processors.
This vulnerability allows a malicious attacker to escalate system privileges. Through this vulnerability, this attacker has the ability to manipulate the AGESA microcode of the UEFI firmware. In this way, malicious code could be executed that would not be detected by the operating system, which is a very serious vulnerability.
[amazon box="B07STGGQ18"]AMD processors suffer from a unique vulnerability
The company has indicated that it has a mitigation ready that is integrated into the microcode and that allows to solve the problem. AMD indicates that correcting this issue does not impact processor performance. Unfortunately AMD has been quite opaque and has not specified which processors and embedded APUs are affected. On the positive side, this attack requires physical or administrative access to the system, so exploiting the vulnerability is very difficult.
AMD statement
AMD is aware of new research related to a potential vulnerability in AMD software technology supplied to motherboard manufacturers for use in their UEFI infrastructure and plans to complete delivery of updated versions designed to mitigate the issue by the end of June. 2020.
The targeted attack described in the research requires privileged physical or administrative access to a system based on a select group of AMD notebooks or embedded processors. If this level of access is acquired, an attacker could potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code without being detected by the operating system.
AMD believes this only affects certain customers and embedded APUs released between 2016 and 2019. The company has delivered most of the updated versions of AGESA to our motherboard partners and plans to deliver the remaining versions by the end of June 2020. AMD recommends following the best security practice of keeping devices up to date with the latest patches. End users who have questions about whether their system works with these latest versions should contact their motherboard manufacturer or original equipment / system manufacturer.
We thank Danny Odler for his continued security investigation.
Source: wccftech