News Score: Score the News, Sort the News, Rewrite the Headlines

AMD: Microcode Signature Verification Vulnerability

Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches. We have demonstrated the ability to craft arbitrary malicious microcode patches on Zen 1 through Zen 4 CPUs. The vulnerability is that the CPU uses an insecure hash function in the signature validation for microcode updates. This vulnerability could be used by an...

Read more at github.com

© News Score  score the news, sort the news, rewrite the headlines