AMD confirms high-severity Ryzen TPM vulnerability and details fixes

AMD unveils “High” severity security flaws with its TPM 2.0 implementation

AMD has published a security bulletin detailing high-severity security vulnerabilities with its TPM 2.0 implementation. The two vulnerabilities have CVSS scores of 8.5 and 8.3, giving them a High severity rating. These issues primarily impact AMD Ryzen processors.

Thankfully, firmware updates have already been provided to motherboard manufacturers that address these security concerns. Furthermore, both attacks require local system access with elevated privileges. This limits what attackers can do using these vulnerabilities. Regardless, AMD Ryzen CPU users should update their motherboard’s firmware to mitigate these vulnerabilities.

AMD Ryzen 3000-9000 series desktop CPUs are affected, as are various Ryzen mobile CPUs and Threadripper series CPUs. Fixes have been available for AMD’s AM4 and AM5 platforms since May. This has given motherboard manufacturers plenty of time to release new motherboard BIOSes that implement AMD’s TPM fixes.

The Trusted Computing Group (TCG) Vulnerability Response Team (VRT) has reported a potential out of bounds (OOB) read vulnerability in the Trusted Platform Module (TPM) 2.0 reference implementation code. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0 whose firmware is based on an affected TCG reference implementation.  If successfully exploited, the vulnerability could allow an attacker to read data stored in the TPM or potentially impact TPM availability.

AMD has analysed the Trusted Computing Group’s report and believes Firmware TPMs on AMD platforms are impacted by this vulnerability.

– AMD

(Details from AMD’s Security Bulletin)

These vulnerabilities came to light through the Trusted Computing Group and its Vulnerability Response Team. They learned of the vulnerability through Intel security researchers.

Thankfully, these vulnerabilities were discovered by security researchers, not bad actors. AMD has been able to address these issues before bad actors could utilise them. That said, the nature of these attacks limits the scope of their use. Regardless, AMD PC users should update their motherboard’s BIOS to ensure that their systems are secure.

You can join the discussion on AMD’s TPM security flaws for Ryzen CPUs on the OC3D Forums.

Mark Campbell

Mark Campbell

A Northern Irish father, husband, and techie that works to turn tea and coffee into articles when he isn’t painting his extensive minis collection or using things to make other things.

Follow Mark Campbell on Twitter
View more about me and my articles.

Uh-oh! It looks like you're using an ad blocker.

OC3D relies on ads to provide free content and sustain our operations. By white listing us on your ad blocker, you help support us and ensure we can continue offering valuable content without any cost to you. We only run our own hand picked ads from Industry brands like MSI, BeQuiet, Sapphire and PC-Specialist - meaning they are all relevent to the content you are reading.

We truly appreciate your understanding and support. Thank you for considering whitelisting OC3D