Breaking News

ASUS Announces WiFi 8 Router DJI Launches Osmo 360 II Razer introduces Clio X Wireless Speaker Head Cushion That Delivers THX Spatial Audio LiberNovo Showcases Ergonomic Innovation at IFA 2026 with Maxis Series for Big And Tall Users TIMEKETTLE UNVEILS NEW W4 PLUS AI INTERPRETER EARBUDS EXPANDING REAL-TIME TRANSLATION ACROSS CALLS, MEETINGS AND MULTIMEDIA CONTENT

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed

Search form

AMD to Fix 13 processors Vulnerabilities Reported by  CTS Labs Research

AMD to Fix 13 processors Vulnerabilities Reported by CTS Labs Research

PC components Mar 20,2018 0

AMD has released the first update regarding the security vulnerabilities involving some AMD products reported by CTS Labs, and the first updates are coming in the following weeks.

The security issues identified by the third-party researchers are not related to the AMD Zen CPU architecture or the Google Project Zero exploits made public Jan. 3, 2018. These issues are associated with the firmware managing the embedded security control processor in some of AMD products (AMD Secure Processor) and the chipset used in some socket AM4 and socket TR4 desktop platforms supporting AMD processors.

AMD has completed its assessment and is in the process of developing and staging the deployment of mitigations. All the issues raised in the research require administrative access to the system, a type of access that effectively grants the user unrestricted access to the system and the right to delete, create or modify any of the folders or files on the computer, as well as change any settings. Any attacker gaining unauthorized administrative access would have a wide range of attacks at their disposal well beyond the exploits identified in this research. Further, all modern operating systems and enterprise-quality hypervisors today have many effective security controls, such as Microsoft Windows Credential Guard in the Windows environment, in place to prevent unauthorized administrative access that would need to be overcome in order to affect these security issues.

The security issues identified are grouped into three major categories. The table below describes the categories, the AMD assessment of impact, and planned actions:

Vulnerability Groups

Problem Description & Method of Exploitation

Potential Impact

Planned AMD Mitigation

MASTERKEY

and

PSP Privilege Escalation

(AMD Secure Processor or "PSP"firmware)

Issue: Attacker who already has compromised the security of a system updates flash to corrupt its contents. AMD Secure Processor (PSP) checks do not detect the corruption.

 

Method: Attacker requires Administrative access

Attacker can circumvent platform security controls. These changes are persistent following a system reboot.

Firmware patch release through BIOS update. No performance impact is expected.

 

AMD is working on PSP firmware updates that we plan to release in the coming weeks.

 

RYZENFALL and FALLOUT

 

(AMD Secure Processor firmware)

 

Issue: Attacker who already has compromised the security of a system writes to AMD Secure Processor registers to exploit vulnerabilities in the interface between x86 and AMD Secure Processor (PSP).

 

Method: Attacker requires Administrative access.

 

Attacker can circumvent platform security controls but is not persistent across reboots.

 

Attacker may install difficult to detect malware in SMM (x86).

 

Firmware patch release through BIOS update. No performance impact is expected.

 

AMD is working on PSP firmware updates that we plan to release in the coming weeks.

Promotory
Chipset

CHIMERA

"Promontory"chipset used in many socket AM4 desktop and socket TR4 high-end desktop (HEDT) platforms.

AMD EPYC server platforms, EPYC and Ryzen Embedded platforms, and AMD Ryzen Mobile FP5 platforms do not use the "Promontory"chipset.

Issue: Attacker who already has compromised the security of a system installs a malicious driver that exposes certain Promontory functions.

 

Method: Attacker requires Administrative access.

Attacker accesses physical memory through the chipset.

 

Attacker installs difficult to detect malware in the chipset but is not persistent across reboots.

Mitigating patches released through BIOS update. No performance impact is expected.

 

AMD is working with the third-party provider that designed and manufactured the "Promontory"chipset on appropriate mitigations.

Mark Papermaster, Senior Vice President and Chief Technology Officer at AMD, promised to provide additional updates on both the company's analysis of these issues and the related mitigation plans in the coming weeks.

Tags: AMD
Previous Post
Facebook to Respond to FTC Questions Over Cambridge Analytica Case
Next Post
Microsoft Announces Project Denali SSD For Cloud-scale Applications

Related Posts

  • G.SKILL Launches Flare X5X Series with AMD EXPO Ultra Low Latency

  • AMD Advances the Hybrid Future of Quantum Computing

  • AMD Expands AMD Ryzen PRO 9000 Series Processor Lineup

  • AMD Launches Ryzen 9 9950X3D2 Dual Edition Processor

  • MINISFORUM Showcases Agent Computing Solutions

  • Samsung and AMD Expand Strategic Collaboration on Next-Generation AI Memory Solutions

  • AMD Ryzen AI PRO 400 Series CPUs Deliver Advanced AI for Desktops

  • AMD at CES 2026

Latest News

ASUS Announces WiFi 8 Router
Enterprise & IT

ASUS Announces WiFi 8 Router

DJI Launches Osmo 360 II
Cameras

DJI Launches Osmo 360 II

Razer introduces Clio X Wireless Speaker Head Cushion That Delivers THX Spatial Audio
Consumer Electronics

Razer introduces Clio X Wireless Speaker Head Cushion That Delivers THX Spatial Audio

LiberNovo Showcases Ergonomic Innovation at IFA 2026 with Maxis Series for Big And Tall Users
Consumer Electronics

LiberNovo Showcases Ergonomic Innovation at IFA 2026 with Maxis Series for Big And Tall Users

TIMEKETTLE UNVEILS NEW W4 PLUS AI INTERPRETER EARBUDS EXPANDING REAL-TIME TRANSLATION ACROSS CALLS, MEETINGS AND MULTIMEDIA CONTENT
Enterprise & IT

TIMEKETTLE UNVEILS NEW W4 PLUS AI INTERPRETER EARBUDS EXPANDING REAL-TIME TRANSLATION ACROSS CALLS, MEETINGS AND MULTIMEDIA CONTENT

Popular Reviews

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

The Quiet Technology Behind the Spin

The Quiet Technology Behind the Spin

SoundPeats Cove Pro

SoundPeats Cove Pro

Akaso Brave 8 Lite

Akaso Brave 8 Lite

Kioxia Exceria Plus G3 512GB microSD

Kioxia Exceria Plus G3 512GB microSD

be quiet! Dark Perk Mice

be quiet! Dark Perk Mice

SoundPeats C30

SoundPeats C30

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed