bk99.de entertain the web since 1997

CPU security hole in AMD processors enables malware infections

Summary

At DEF CON 2024, IOActive researchers Enrique Nissim and Krzysztof Okupski presented the “Sinkclose” hole, which affects AMD processors of roughly the last ten years up to Ryzen 7000. Attackers with kernel access can use it to execute code in the privileged System Management Mode and hide from the operating system and protective software. Such an infection even survives a reinstallation and can only be prevented by a firmware update.

Ideas

  • System Management Mode sits above the operating system and hypervisor.
  • Malware in this mode is invisible to conventional protective software.
  • The researchers informed AMD as early as October 2023.
  • AMD emphasised that an attack already requires kernel access.

Insights

  • High barriers to entry lose weight when hardware is already manipulated in the supply chain.
  • Firmware is a patch target of its own that operating system updates do not cover.

Facts

  • According to the researchers, hundreds of millions of AMD chips are affected.
  • Reinstalling the operating system does not remove an SMM infection.
  • The hole has the identifier CVE-2023-31315; no updates were planned for the Ryzen 3000 series.

References

Critique

  • The report refers to AMD’s bulletin but itself names no firmware versions for comparison.

Recommendations

  • Apply manufacturers’ BIOS and AGESA updates on older AMD systems as well.
  • Treat kernel access on servers as a complete compromise that includes a firmware check.

Read the original article

Search the Web Archive