
Vulnerabilities in Ryzen processors | Exploits of the Meltdown-Spectre type
One of the new security vulnerabilities found in AMD’s Ryzen processors and Epic series can allow 13 new exploits. Based on research conducted at CTS-Labs, we learn that one of the vulnerabilities involves Secure Encrypted Virtualization technology, introduced by the company’s ZEN architecture, through which an attacker can penetrate Microsoft Windows Credential Guard.
All 13 exploits are of the Meltdown-Spectre type. They can give malicious users access to stored data and the systems themselves.They were named Ryzenfall, Fallout, Chimera and Masterkey. These vulnerabilities allow malicious actors to gain unauthorized access to sensitive information stored in a computer’s memory, such as passwords and other sensitive data.
For example, the Ryzenfall vulnerability specifically affected Ryzen processors with Secure Processor firmware versions prior to 4.0, allowing an attacker to gain access to the Secure Processor and potentially execute malicious code. The Masterkey vulnerability, on the other hand, allowed an attacker to modify the firmware on the processor. He coulde then gain access to sensitive information.
It is important to note that these vulnerabilities required a attacker to have physical access to the targeted system and to have administrative access to it. Additionally, it is also important to keep in mind which company discovered and reported these vulnerabilities. The company that reported them has a vested interest in the security of Ryzen processors and that some experts have raised questions about the way CTS Labs reported the vulnerabilities.
Gather more information on the matter. Continue reading by following the link, https://thehackernews.com/2018/03/amd-processor-vulnerabilities.html.
If you liked this article, then you might also enjoy this one.
Author: PC-GR
The World of Technology
