AMD To Release Firmware Updates for Newly Disclosed Chip Flaws

AMD indicated on Wednesday that it is working on firmware updates to address processor security issues publicized last week by CTS Labs.

The security issues mostly concerned the Platform Security Processor that's present on AMD processors, as well as a Promontory chipset. However, attackers would need to have administrative access to exploit the flaws, and it's considered to be a difficult feat to carry out. Independent consultancy Trail of Bits, which tested and affirmed the exploits on behalf of CTS Labs, downplayed the security risks.

"There is no immediate risk of exploitation of these vulnerabilities for most users," Trail of Bits indicated in an announcement. "Even if the full details were published today, attackers would need to invest significant development efforts to build attack tools that utilize these vulnerabilities."

CTS Labs, a security consultancy for chip manufacturers, had published a white paper (PDF) describing the exploits, but it indicated that "all technical details that could be used to reproduce the vulnerabilities have been redacted." It tested the flaws on "AMD's latest Zen processors for the past six months, including EPYC, Ryzen, Ryzen Pro and Ryzen Mobile," according to the white paper. The white paper claimed that organizations were at "significantly increased risk of cyber-attacks" from the flaws. It also was unsparing about AMD's security oversight.

"In our opinion, the basic nature of some of these vulnerabilities amounts to complete disregard of fundamental security principles," the white paper stated. "This raises concerning questions regarding security practices, auditing, and quality controls at AMD."

This week, AMD described the vulnerabilities and its mitigation plans in an announcement. The flaws aren't associated with the Meltdown and Spectre issues identified in early January by Google's Project Zero, according to Mark Papermaster, AMD's chief technology officer and senior vice president of technology and engineering. He indicated that AMD will release firmware updates in the coming weeks to address the flaws. Papermaster also downplayed the security threats.

"It's important to note that all the issues raised in the research require administrative access to the system, a type of access that effectively grants the user unrestricted access to the system and the right to delete, create or modify any of the folders or files on the computer, as well as change any settings," he wrote. "Any attacker gaining unauthorized administrative access would have a wide range of attacks at their disposal well beyond the exploits identified in this research."

Papermaster added that there are additional controls, "such as Microsoft Windows Credential Guard in the Windows environment," to ward off unauthorized administrative access.

AMD was informed about the flaws by CTS Labs on March 12, 2018, but it was given just one day before CTS Labs published its findings, according to Papermaster. Some organizations, such as Google, have suggested that coordinated disclosure of security flaws should be about 90 days.

About the Author

Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.


  • Secured-Core PCs Promise To Stop Malware at the Firmware Level

    Microsoft and its hardware partners recently described new "Secured-core" PCs, which add protections against firmware-based attacks.

  • How To Ransomware-Proof Your Backups: 4 Key Best Practices

    Backups are the only guaranteed way to save your data after a ransomware attack. Here's how to make sure your backup strategy has ransomware mitigation built right in.

  • Microsoft Buys Mover To Aid Microsoft 365 Shifts

    Microsoft announced on Monday that it bought Mover to help organizations migrate data and shift to using Microsoft 365 services.

  • Microsoft Explains Windows 7 Extended Security Updates Setup Process

    Microsoft this week described installation instructions for volume licensing users of Windows 7 Service Pack 1 to get Extended Security Updates (ESU) activated on PCs.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.