In AMD chips, vulnerability was found on Zen 4 architectures from Zen 4, which allows you to steal data and capture systems

According to this practice, developers and researchers in the field of information security inform suppliers of compromised products about their discoveries, so that they have the opportunity to eliminate the gaps. Only after that the information about them is publicized. In September last year, Google found vulnerabilities in the AMD EPYC processors of the server class related to Zen 4 architectures.

Image Source: AMD

As noted by the authors of the ballot, the found vulnerability allowed attackers with the rights of a local administrator to load the malicious patches of the microcode, launch malicious software on the virtual machines of the victim and gain access to his data. The vulnerability is that the processor uses an unsafe hash-function when checking the signature signatures of the microcode. This vulnerability can be used by attackers to compromise confidential computing workloads, protected by the latest version of AMD Security Encrypted Virtualization, SEV-SNP, or for compromising Dynamic Root of Trust Measurement.

Epyc Naples, Rome, Milan and Genoa server processors were at risk, but Google experts transferred all the information necessary to eliminate vulnerability to confidential channels on September 25 last year, after which by December 17, AMD was able to distribute the necessary updates among its customers.

Having withstand the AMD pause necessary for the full elimination of vulnerabilities, Google reported the found vulnerability on GitHub pages. In order to additionally protect AMD customers, Google representatives have promised additional details about vulnerability and tools for working with it no earlier than March 5 of this year.

admin

Share
Published by
admin

Recent Posts

Nintendo reported on a drop in sales of consoles by 30 % and 24 % games – everyone is waiting for Switch 2

Now in the calendar of the Japanese Nintendo Corporation in full swing is the last…

5 minutes ago

Step forward and two ago: Sid Meier’s Civilization VII became the lowest license plate in the history of the series

The ambitious global Sid Meier’s Civilization VII strategy from developers from the Firaxis Games studio…

2 hours ago

Electronic Arts froze the NEED For Speed ​​series for the new Battlefield, but there is also good news

Executive Vice-President of Electronic Arts and the head of the Battlefield franchise Vince Zampella in…

3 hours ago

Trump ordered the creation of a sovereign investment fund in the United States, which could buy Tiktok

Having more or less dealing with priority political and economic tasks, US President Donald Trump…

3 hours ago