Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
AMD APUs Affected by SMM Callout Privilege Escalation Security Vulnerability
#1
Exclamation 
Quote:
[Image: GsqzdCGKm9fGBPS4Xnyzpn-970-80.jpg]

AMD is distributing the fix.

Yesterday, AMD disclosed the SMM Callout Privilege Escalation (CVE-2020-12890) vulnerability that affects the chipmaker's client and embedded APUs that came out between 2016 and 2019.

SMM Callout Privilege Escalation, which security research Danny Odler discovered, enables an attacker with physical or administrative access to the victim system to manipulate the AMD Generic Encapsulated Software Architecture (AGESA) microcode inside the motherboard's firmware. This allows for the execution of malicious code that's not detectable by the operating system. 
  
Luckily, this vulnerability can be mitigated with a simple microcode update, which seemingly doesn't bear a performance impact on the system. AMD has already distributed updated versions of its AGESA microcodes to its motherboard partners and will deliver the remaining versions by the end of this month. 

As usual, AMD recommends users to update their systems to the latest firmware once it's available.
...
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Messages In This Thread
AMD APUs Affected by SMM Callout Privilege Escalation Security Vulnerability - by harlan4096 - 19 June 20, 07:04

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD reportedly set to launch EPYC 4004 ...
AMD EPYC 4004 Zen4 “...harlan4096 — 11:04
Kaspersky 21.17.7.539
Kaspersky 21.17.7....harlan4096 — 07:32
Free Download Manager 6.22.0.5714
Changes in 6.22.0....harlan4096 — 07:28
Advanced Renamer 3.95
Changes in 3.95: ...harlan4096 — 07:28
Brave 1.65.123
Release Channel 1....harlan4096 — 07:26

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>