AMD CPUs affected by a new chipset vulnerability

There is a new vulnerability in the market and AMD has finally shared some details about it. The new chipset vulnerability can allow non-privileged users to read and dump some types of memory pages in Windows.

This technique will allow an attacker to easily steal passwords or enable other types of attacks, which even includes circumventing standard KASLR exploitation mitigations. This latest information about the above-mentioned chipset vulnerability came out as a part of a coordinated disclosure with Kyriakos Economou, a security researcher and co-founder of ZeroPeril.

Kyriakos Economou has previously exploited the vulnerability to downloaded several gigabytes of sensitive data from impacted AMD processors and it did this as a non-admin user. AMD has prepared mitigations that can be downloaded either as part of its latest chipset drivers or by using Windows Update to update the AMD PSP driver.

The patch was originally issued by AMD several weeks ago, however, it was without disclosing which vulnerabilities were addressed. But this new disclosure has answered all those questions. According to sources, the security researchers first discovered the flaw with Ryzen 2000- and 3000-series chips, however, initially AMD had listed only the Ryzen 1000 and older chips in its advisory.

But, Kyriakos Economou noted the discrepancy and followed up with AMD about the issue. The chipmaker was quick enough to update the page with a full list of impacted processors that spans its entire modern consumer processor lineup as well as many older models.

The models affected are given below(Updated list):

Affected AMD Processors

  • 2nd Gen AMD Ryzen Mobile Processor with Radeon Graphics 
  • 2nd Gen AMD Ryzen Threadripper processor
  • 3rd Gen AMD Ryzenâ„¢ Threadripperâ„¢ Processors
  • 6th Generation AMD A-series CPU with Radeonâ„¢ Graphics
  • 6th Generation AMD A-Series Mobile Processor  
  • 6th Generation AMD FX APU with Radeonâ„¢ R7 Graphics 
  • 7th Generation AMD A-Series APUs
  • 7th Generation AMD A-Series Mobile Processor  
  • 7th Generation AMD E-Series Mobile Processor
  • AMD A4-Series APU with Radeon Graphics 
  • AMD A6 APU with Radeon R5 Graphics
  • AMD A8 APU with Radeon R6 Graphics
  • AMD A10 APU with Radeon R6 Graphics
  • AMD 3000 Series Mobile Processors with Radeonâ„¢ Graphics 
  • AMD Athlon 3000 Series Mobile Processors with Radeonâ„¢ Graphics  
  • AMD Athlon Mobile Processors with Radeonâ„¢ Graphics 
  • AMD Athlon X4 Processor
  • AMD Athlonâ„¢ 3000 Series Mobile Processors with Radeonâ„¢ Graphics 
  • AMD Athlonâ„¢ X4 Processor
  • AMD E1-Series APU with Radeon Graphics
  • AMD Ryzenâ„¢ 1000 series Processor
  • AMD Ryzenâ„¢ 2000 series Desktop Processor
  • AMD Ryzenâ„¢ 2000 series Mobile Processor  
  • AMD Ryzenâ„¢ 3000 Series Desktop Processor
  • AMD Ryzenâ„¢ 3000 series Mobile Processor with  Radeonâ„¢ Graphics  
  • AMD Ryzenâ„¢ 3000 series Mobile Processor 
  • AMD Ryzenâ„¢ 4000 Series Desktop Processor with Radeonâ„¢ Graphics
  • AMD Ryzenâ„¢ 5000 Series Desktop Processor
  • AMD Ryzenâ„¢ 5000 Series Desktop Processor with Radeonâ„¢ Graphics 
  • AMD Ryzenâ„¢ 5000 Series Mobile Processors with Radeonâ„¢ Graphics
  • AMD Ryzenâ„¢ Threadripperâ„¢ PRO Processor
  • AMD Ryzenâ„¢ Threadripperâ„¢ Processor

In its research, Economou attacked two separate issues with AMD’s amps.sys driver for its Platform Security Processor (PSP). The vulnerability allowed them to easily extract multiple gigabytes of the uninitialized physical memory page. Here’s a summary from their report:

“During our tests, we managed to leak several gigabytes of uninitialized physical pages by allocating and freeing blocks of 100 allocations continuously until the system was not able to return a contiguous physical page buffer.

The contents of those physical pages varied from kernel objects and arbitrary pool addresses that can be used to circumvent exploitation mitigations such as KASLR, and even registry key mappings of \Registry\Machine\SAM containing NTLM hashes of user authentication credentials that can be used in subsequent attack stages.

For example, these can be used to steal credentials of a user with administrative privilege and/or be used in pass-the-hash style attacks to gain further access inside a network.”

AMD has issued advice to the users with impacted CPUs to update to AMD PSP driver 5.17.0.0 via Windows Update or to AMD Chipset Driver 3.08.17.735 or newer in the future. AMD’s chipset vulnerability disclosure comes on the heels of news that all of its processors suffer from a Meltdown-like vulnerability.

source

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More like this

AMD’s Medusa Point APUs May Stick with RDNA 3.X Instead of RDNA 4 or 5 – What It Means for Gamers

AMD’s Medusa Point APUs May Stick with RDNA 3.X...

AMD’s next-gen Medusa Point APUs, set to feature the powerful Zen 6 architecture, might not be upgrading...
AMD AERITH Plus SoC: A Powerhouse Upgrade for Steam Deck 2?

AMD AERITH Plus SoC: A Powerhouse Upgrade for Steam...

AMD is reportedly preparing a next-generation AERITH Plus SoC, designed to push the performance boundaries of handheld...
AMD Ryzen AI 5 340 Benchmarks on Geekbench: Radeon 840M Outperforms 740M by 19% in OpenCL Test

AMD Ryzen AI 5 340 on Geekbench: Radeon 840M...

In the ever-evolving world of computing, performance is paramount, but affordability often becomes a key deciding factor...
AMD Ryzen-Powered Handhelds: Revolutionizing the Gaming Landscape with Millions of Units Sold

AMD Ryzen-Powered Gaming Handhelds: Millions of Units Sold

The handheld gaming scene has undergone a radical transformation in recent years. Once a niche category, portable...
AMD Ryzen 7 9800X3D Faces Widespread CPU Failures—ASRock Motherboards Most Affected

AMD Ryzen 7 9800X3D Faces Widespread CPU Failures—ASRock Motherboards...

The tech community is buzzing with concerns as AMD’s highly sought-after Ryzen 7 9800X3D processor faces a...

LATEST NEWS

WPL 2025: Mooney, Dottin, And Kanwar Shine As Giants Secure Dominant Win To Climb To Second Place

It was far from a joyful homecoming for UP Warriorz, who suffered a heavy defeat against Gujarat Giants at the Ekana Stadium, slipping from...

UEFA Champions League 2024/25: Real Madrid vs Atletico Madrid – Preview and Prediction and Where to Watch the Match Live?

Real Madrid aims to capitalize on home advantage as they welcome fierce rivals Atlético for the first leg of their Champions League last-16 clash...

Exclusive: The Top 10 PC Games Available on MacOS as of 2025

PC Games Available on macOS: While macOS has never been as synonymous with gaming as Windows, there are a growing number of excellent titles...

ASUS Brings AMD Radeon RX 9070 Series GPUs: The Future of Gaming Graphics

Picture this: You’re immersed in the latest open-world game, marveling at the lifelike reflections in a rain-soaked city street, when suddenly you realize -...

Featured