{"id":4822,"date":"2024-08-12T15:14:47","date_gmt":"2024-08-12T20:14:47","guid":{"rendered":"https:\/\/www.darkreading.com\/remote-workforce\/amd-issues-updates-for-silicon-level-sinkclose-flaw"},"modified":"2024-08-12T15:14:47","modified_gmt":"2024-08-12T20:14:47","slug":"amd-issues-updates-for-silicon-level-sinkclose-processor-flaw","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/12\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw\/","title":{"rendered":"AMD Issues Updates for Silicon-Level &#8216;SinkClose&#8217; Processor Flaw"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt766079a26ab506e2\/66ba61172463586736fb9000\/amd_JHVEPhoto_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AMD has issued firmware updates to address a nearly two-decades-old silicon-level vulnerability it its EPYC data center processors and its line of Ryzen processors for PCs and embedded systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The flaw affects a component in the processor for protecting System Management Mode (SMM), an execution mode so protected in the processor that it is even more privileged than kernel-level mode. Researchers from IOActive who discovered the privilege escalation vulnerability described it as an &#8220;unpatchable&#8221; issue that, if exploited, would allow an attacker to implant malware on a system that would be almost impervious to removal attempts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Hundreds of millions of devices worldwide currently have AMD chips that contain the vulnerability.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The SinkClose Flaw\">The SinkClose Flaw<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The &#8220;SinkClose&#8221; vulnerability, as IOActive researchers have dubbed it, is somewhat similar to &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.blackhat.com\/docs\/us-15\/materials\/us-15-Domas-The-Memory-Sinkhole-Unleashing-An-x86-Design-Flaw-Allowing-Universal-Privilege-Escalation-wp.pdf\" rel=\"noopener\">Memory Sinkhole<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; an SMM-bypass vulnerability in Intel Sandy Bridge and prior processors that security researcher Christopher Domas disclosed at a Black Hat presentation in 2015. Domas has also uncovered <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/hacker-unlocks-god-mode-and-shares-the-key-\" rel=\"noopener\">other hardware level vulnerabilities<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in Intel chips.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The vulnerability is nearly impossible to fix in computers that aren&#8217;t configured correctly \u2014 which is the case for most systems,&#8221; IOActive said in a statement. &#8220;In properly configured systems, the vulnerability could lead to malware infections \u2014 known as bootkits \u2014 that are nearly impossible to detect.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AMD itself has described the vulnerability as an issue that gives attackers who already have ring0 \u2014 or kernel level \u2014 access to an affected system a way to potentially modify the SMM even if SMM Lock, a feature for preventing unauthorized SMM modifications, is turned on. &#8220;Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMM Lock is enabled, potentially leading to arbitrary code execution,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7014.html\" rel=\"noopener\">the chip vendor said<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">SMM is a mode on AMD chips for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/csrc.nist.gov\/glossary\/term\/system_management_mode#:~:text=Definitions%3A,a%20segregated%20block%20of%20memory.\" rel=\"noopener\">low-level system management functions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. It only executes code from a segregated block of memory called system management random access memory, or SMRAM. AMD chips implement a memory controller called TSeg to protect access to SMRAM.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"SMM Bypass Attack\">SMM Bypass Attack<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, IOActive researchers Enrique Nissim and Krzysztof Okupski found a way to overcome these protections and get SMM to essentially execute code of their choice from outside the SMRAM. They did this by leveraging a feature called TClose that AMD incorporated into its chips for backward compatibility with a legacy memory management feature. Dumas&#8217; SinkHole flaw involved a similar legacy feature in Intel chips.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Nissim and Okupski determined an attacker could use the SinkClose flaw to drop malware deep enough \u2014 and persistent enough \u2014 inside a system to make it invisible to the operating system, the hypervisor, and to all endpoint detection mechanisms. In a talk at the DEF CON hacker conference on Aug. 10, the researchers described the vulnerability as something a remote attacker would be able to exploit. However, an adversary would need an in-depth understanding of AMD chip architecture \u2014 something that only a nation-state-level would likely possess \u2014 to be able to exploit it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AMD itself has contended by way of background context that an attacker with the level of access required to exploit the SinkClose vulnerability would already have the ability to read, modify, erase, and snoop on everything on the computer. In addition, someone with operating system kernel-level access can also disable security mechanisms and prevent a computer from booting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is akin to having the knowledge to break into a safe deposit box at the bank,&#8221; AMD noted in an email to Dark Reading. &#8220;In the real world, to get to the box, a burglar must first get past the alarms, the guards, the vault door and its own locks, clearly not an easy task.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An attacker with the skills and knowledge to execute an SMM bypass attack could install malware of the sort IOActive has warned about. But it wouldn&#8217;t be the first time attackers have deployed such malware, AMD said by way of background, pointing to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/russia-s-sednit-deploys-first-firmware-level-rootkit-in-the-wild\" rel=\"noopener\">Lojax firmware-level rootkit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from 2018. &#8220;While this malware may be stealthy, it is not invisible or impossible to remediate.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;AMD&nbsp;has released mitigation options&nbsp;for its&nbsp;AMD&nbsp;EPYC datacenter products and&nbsp;AMD&nbsp;Ryzen PC products,&#8221; the chipmaker said. &#8220;A full list of impacted products and mitigation options is available in our <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"http:\/\/www.amd.com\/productsecurity\" rel=\"noopener\">product security bulletin<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/remote-workforce\/amd-issues-updates-for-silicon-level-sinkclose-flaw\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AMD has issued firmware updates to address a nearly two-decades-old<\/p>\n","protected":false},"author":12,"featured_media":4823,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4822","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/amd-issues-updates-for-silicon-level-sinkclose-processor-flaw.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4822"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4822\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4823"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4822"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4822"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}