Now, AMD has provided a response to the issue. According to a blog post published on Tuesday, the security issues identified by CTS Labs are not related to AMD's Zen architecture or the vulnerabilities disclosed by Google.
Last week, security CTS labs was in the news for revealing 13 critical vulnerabilities in AMD's Ryzen and Epyc processors.
"These issues are related to the firmware that manages the embedded security control processor in some of our products (AMD Secure Processor) and the chipset used in some AM4 and socket TR4 desktop platforms that support AMD processors.".
AMD: Security vulnerabilities can be exploited by attackers
However, AMD also notes that the vulnerabilities can only be exploited if attackers have administrator (or root) access to the system – an opportunity that allows them to do anything from delete, create, or modify files or folders, to change settings. In short, it’s like taking control of the system.
However, modern operating systems have built-in security measures to prevent unauthorized administrative access. For example, Microsoft Windows Credential Guard.
AMD will release firmware patches via BIOS updates in the coming weeks to fix the new vulnerabilities, which have been classified as RYZENFALL, FALLOUT, and CHIMERA. The company said that the performance of the devices will not be affected.
Promptly applying updates is very important for protecting systems and obtaining new security features.
