AMD has reportedly fixed, but has not yet released updates to the general public for a security flaw affecting the AMD Secure processor.
This component, formerly known as the AMD PSP (Platform Security Processor), is a chip-on-chip security system , similar to Intel 's Management Engine (ME) .
Just like Intel ME processors, AMD Secure Processor is an integrated coprocessor that sits alongside the actual AMD64 x86 CPU cores and features a separate processing system that is tasked with handling various security-related functions.
Cfir Cohen, a security researcher on the Google Cloud Security team, reports that he discovered a vulnerability in the AMD Secure processor's Trusted Platform Module (TPM).
The TPM is a component for storing critical system data, such as passwords, certificates, and encryption keys, and is located in a “secure” environment and outside of AMD’s more easily accessible cores.
“Through static analysis, we found a stack overflow in the EkCheckCurrentCert function,” Cohen says. The researcher claims that an attacker could use specially crafted EK certificates to gain remote code execution privileges on the AMD Secure processor, effectively breaching its security.
Cohen said that some key mitigation techniques, such as stack cookies, NX stack, and ASLR, “have not been implemented in AMD’s Secure Processor to date, making the exploit very easy.”.
Intel ME processors use a similar TPM module, but Cohen does not say whether it is affected.
The Google researcher reported the flaw to AMD in September, and AMD told the researcher in December that it had developed an updated version and was preparing for release
Coincidentally, on Reddit [1, 2], some reported seeing a new option that allows AMD PSP to be disabled, but it is unclear whether this new option is related to the updates AMD is reporting regarding Cohen's findings.
It's worth mentioning that an option to disable PSP is somewhat unique in the CPU world. For example, Intel has never allowed users to disable its secret collaborator, despite the long list of security flaws that have been reported for this component.
Cohen's revelation about the AMD Secure Processor flaw came on the same day that Google researchers revealed details about the Meltdown and Spectre flaws that affect most of the world's CPUs.
Last November, Intel again released updates for several similar vulnerabilities in Intel ME that allowed attackers to install rootkits and recover data from secure parts of Intel processors.
