Hardware

AMD processors suffer a unique vulnerability, but we don't know which ones

To date, the vulnerabilities that have appeared mainly affect Intel processors. It has now been made known by AMD that select processors and APUs released between 2016 and 2019 suffers a vulnerability. This vulnerability is called SMM Callout Privilege Escalation Vulnerability and has been labeled CVE-2020-12890. That we know of is the first to date that only affects AMD processors.

This vulnerability allows a malicious attacker to escalate system privileges. Through this vulnerability, this attacker has the ability to manipulate the AGESA microcode of the UEFI firmware. In this way, malicious code could be executed that would not be detected by the operating system, which is a very serious vulnerability.

[amazon box="B07STGGQ18"]

AMD processors suffer from a unique vulnerability

The company has indicated that it has a mitigation ready that is integrated into the microcode and that allows to solve the problem. AMD indicates that correcting this issue does not impact processor performance. Unfortunately AMD has been quite opaque and has not specified which processors and embedded APUs are affected. On the positive side, this attack requires physical or administrative access to the system, so exploiting the vulnerability is very difficult.

AMD statement

AMD is aware of new research related to a potential vulnerability in AMD software technology supplied to motherboard manufacturers for use in their UEFI infrastructure and plans to complete delivery of updated versions designed to mitigate the issue by the end of June. 2020.

The targeted attack described in the research requires privileged physical or administrative access to a system based on a select group of AMD notebooks or embedded processors. If this level of access is acquired, an attacker could potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code without being detected by the operating system.

AMD believes this only affects certain customers and embedded APUs released between 2016 and 2019. The company has delivered most of the updated versions of AGESA to our motherboard partners and plans to deliver the remaining versions by the end of June 2020. AMD recommends following the best security practice of keeping devices up to date with the latest patches. End users who have questions about whether their system works with these latest versions should contact their motherboard manufacturer or original equipment / system manufacturer.

We thank Danny Odler for his continued security investigation.

Source: wccftech

Show more

Robert Sole

Director of Contents and Writing of this same website, technician in renewable energy generation systems and low voltage electrical technician. I work in front of a PC, in my free time I am in front of a PC and when I leave the house I am glued to the screen of my smartphone. Every morning when I wake up I walk across the Stargate to make some coffee and start watching YouTube videos. I once saw a dragon ... or was it a Dragonite?

Related publications

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.