AMD Microcode Signature Verification Vulnerability Let Attackers Load Malicious Patches

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

AMD Microcode Signature Verification Vulnerability Let Attackers Load Malicious Patches

Post by Shane1145 »

Security researchers have uncovered a critical vulnerability in AMD Zen CPUs that allows attackers with elevated privileges to load malicious microcode patches, bypassing cryptographic signature checks.

Dubbed “EntrySign,” this flaw stems from AMD’s use of the AES-CMAC algorithm as a hash function during microcode validation—a design decision that enables collision attacks and signature forgery.


https://cybersecuritynews.com/amd-micro ... erability/
Post Reply