• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

13 Major Vulnerabilities Discovered in AMD Zen Architecture, Including Backdoors

Joined
Dec 29, 2010
Messages
3,457 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
You know, if I didn't care about this potential security problem, and this were a "real-life forum", brick and mortar and all that, I'd totally get me some popcorn and enjoy seeing the fights between AMD-fans, Intel-fans, skeptical people, paranoid people and everyone else. From a safe distance, of course. Maybe set a betting pool too :laugh:

So you're really concerned right? No BS? Take a guess how many articles based their news on these findings?

New York-based cyber security firm Trail of Bits told Reuters that it had verified the findings from CTS, which paid $16,000 for a review of the AMD vulnerabilities.

For the attacks to work, an attacker must first obtain administrator access to a targeted network, Guido said.

https://www.reuters.com/article/us-...irm-says-it-finds-amd-chip-flaw-idUSKCN1GP273

In other news: Home security panels vulnerable to burglars, once they break into the house and befriend the family dog.

Exactly lol!
 
Joined
Feb 18, 2017
Messages
688 (0.26/day)
Take THAT AMD. I dont wanna hear the fanbois anymore.
Before you say anything, have you seen this?


Or have you checked the YT channel comments are disabled? And the domain name amdflaws.com? :D Correct company. :D Ridiculous really. A sue is on the way for sure. BTW, your next comment made it clear that you are an Intel tard.

This has the potential to be even worse than Spectre and Meltdown.

Yes, definitely. :D LOL

It's so funny seeing AMD aficionados going in defense mode :p


No need for that, as this is a complete BS. Wake up and you will see. :)
 
Last edited:
Joined
Dec 29, 2010
Messages
3,457 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
:roll::roll::roll:

^^Hey I recognize those 3 employees now.

 
Joined
Jan 8, 2017
Messages
8,944 (3.36/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
Before you say anything, have you seen this?


Or did you check the YT channel comments are disabled? Correct company. :D

Oh come on , don't be so mean. They mean 16 years of experience as in what their brilliant employees have.
 
Joined
Oct 19, 2007
Messages
8,203 (1.36/day)
Processor Intel i9 9900K @5GHz w/ Corsair H150i Pro CPU AiO w/Corsair HD120 RBG fan
Motherboard Asus Z390 Maximus XI Code
Cooling 6x120mm Corsair HD120 RBG fans
Memory Corsair Vengeance RBG 2x8GB 3600MHz
Video Card(s) Asus RTX 3080Ti STRIX OC
Storage Samsung 970 EVO Plus 500GB , 970 EVO 1TB, Samsung 850 EVO 1TB SSD, 10TB Synology DS1621+ RAID5
Display(s) Corsair Xeneon 32" 32UHD144 4K
Case Corsair 570x RBG Tempered Glass
Audio Device(s) Onboard / Corsair Virtuoso XT Wireless RGB
Power Supply Corsair HX850w Platinum Series
Mouse Logitech G604s
Keyboard Corsair K70 Rapidfire
Software Windows 11 x64 Professional
Benchmark Scores Firestrike - 23520 Heaven - 3670
Joined
Dec 29, 2010
Messages
3,457 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
Oh come on , don't be so mean. They mean 16 years of experience as in what their brilliant employees have.

They implied their company as an entity, not the combined xp of their staff.
 
Joined
Apr 15, 2009
Messages
1,012 (0.18/day)
Processor Ryzen 9 5900X
Motherboard Gigabyte X570 Aorus Master
Cooling ARCTIC Liquid Freezer II 360 A-RGB
Memory 32 GB Ballistix Elite DDR4-3600 CL16
Video Card(s) XFX 6800 XT Speedster Merc 319 Black
Storage Sabrent Rocket NVMe 4.0 1TB
Display(s) LG 27GL850B x 2 / ASUS MG278Q
Case be quiet! Silent Base 802
Audio Device(s) Sound Blaster AE-7 / Sennheiser HD 660S
Power Supply Seasonic Prime 750W Titanium
Software Windows 11 Pro 64
I've just heard that if someone had my car keys and access to my car, they could change the memory positions for my driver's seat! This is an outrage! Where's the whitepaper on this critical exploit?!
 
Low quality post by Dave65
Joined
Mar 7, 2010
Messages
956 (0.19/day)
Location
Michigan
System Name Daves
Processor AMD Ryzen 3900x
Motherboard AsRock X570 Taichi
Cooling Enermax LIQMAX III 360
Memory 32 GiG Team Group B Die 3600
Video Card(s) Powercolor 5700 xt Red Devil
Storage Crucial MX 500 SSD and Intel P660 NVME 2TB for games
Display(s) Acer 144htz 27in. 2560x1440
Case Phanteks P600S
Audio Device(s) N/A
Power Supply Corsair RM 750
Mouse EVGA
Keyboard Corsair Strafe
Software Windows 10 Pro
Joined
Dec 16, 2017
Messages
2,730 (1.18/day)
Location
Buenos Aires, Argentina
System Name System V
Processor AMD Ryzen 5 3600
Motherboard Asus Prime X570-P
Cooling Cooler Master Hyper 212 // a bunch of 120 mm Xigmatek 1500 RPM fans (2 ins, 3 outs)
Memory 2x8GB Ballistix Sport LT 3200 MHz (BLS8G4D32AESCK.M8FE) (CL16-18-18-36)
Video Card(s) Gigabyte AORUS Radeon RX 580 8 GB
Storage SHFS37A240G / DT01ACA200 / WD20EZRX / MKNSSDTR256GB-3DL / LG BH16NS40 / ST10000VN0008
Display(s) LG 22MP55 IPS Display
Case NZXT Source 210
Audio Device(s) Logitech G430 Headset
Power Supply Corsair CX650M
Mouse Microsoft Trackball Optical 1.0
Keyboard HP Vectra VE keyboard (Part # D4950-63004)
Software Whatever build of Windows 11 is being served in Dev channel at the time.
Benchmark Scores Corona 1.3: 3120620 r/s Cinebench R20: 3355 FireStrike: 12490 TimeSpy: 4624
It is possible. There are enough servers with outdated configuration and / or software hooked on the net. But for a succesfull bios update you need to restart the system. This will look very odd a server rebooting out of nowhere. Once that happend the payload could be triggered again and you could take over the complete system. Thus with any credentials that might apply on the machine. But this should trigger any admin in the first place, that something is going on.

There are several approaches to a succesfull attack. One of m might simply stick a USB drive into a running server and exploit it's chipset by a handwritten program. Upload your payload and good to go. But even if you 'hack' apache, your still a user, and a user compared to root has different priveledges. None of them as close to flashing a bios lol.

Yeah, but two things:
1 - I don't know how server motherboards work, but some desktop ones allow you to update the BIOS/UEFI from within Windows. So, maybe you could do the same on some servers? And would it be mandatory to restart immediately? If not, you could wait until the next scheduled restart, with none the wiser.
2 - Privilege-escalation bugs are common in Windows (every month they fix one of those, at least) and Linux has some too (though I don't know if they are as common as their Windows-counterparts). If patches are not applied, someone could just chain a few exploits together and get in.

However, such an outcome may be avoided, at least for a short time, if the system is inside a VM.
 
Joined
Dec 29, 2010
Messages
3,457 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
Joined
Feb 18, 2017
Messages
688 (0.26/day)
Well, if this turns out to be true, it's gonna be a shitstorm for AMD....
Haha, for what reason? Have it caused anything for Intel except for its shitty communication?

Should I? Im not a researcher


I'm not a researcher either, but I found it pretty easily. You should have done so, if you were really interested in the news. In fact, you are only an Intelboy.
 
Joined
Dec 29, 2010
Messages
3,457 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
Yeah, but two things:
1 - I don't know how server motherboards work, but some desktop ones allow you to update the BIOS/UEFI from within Windows. So, maybe you could do the same on some servers? And would it be mandatory to restart immediately? If not, you could wait until the next scheduled restart, with none the wiser.
2 - Privilege-escalation bugs are common in Windows (every month they fix one of those, at least) and Linux has some too (though I don't know if they are as common as their Windows-counterparts). If patches are not applied, someone could just chain a few exploits together and get in.

However, such an outcome may be avoided, at least for a short time, if the system is inside a VM.

Um, maybe you missed it but if you have access to update said bios even in windows, that would mean you already have root/admin... so wtf are you doing? Why even bother with a hack/flaw/bug whatever? Why not get to the business of stealing whatever the eff you are there for?
 

AsRock

TPU addict
Joined
Jun 23, 2007
Messages
18,876 (3.07/day)
Location
UK\USA
Processor AMD 3900X \ AMD 7700X
Motherboard ASRock AM4 X570 Pro 4 \ ASUS X670Xe TUF
Cooling D15
Memory Patriot 2x16GB PVS432G320C6K \ G.Skill Flare X5 F5-6000J3238F 2x16GB
Video Card(s) eVga GTX1060 SSC \ XFX RX 6950XT RX-695XATBD9
Storage Sammy 860, MX500, Sabrent Rocket 4 Sammy Evo 980 \ 1xSabrent Rocket 4+, Sammy 2x990 Pro
Display(s) Samsung 1080P \ LG 43UN700
Case Fractal Design Pop Air 2x140mm fans from Torrent \ Fractal Design Torrent 2 SilverStone FHP141x2
Audio Device(s) Yamaha RX-V677 \ Yamaha CX-830+Yamaha MX-630 Infinity RS4000\Paradigm P Studio 20, Blue Yeti
Power Supply Seasonic Prime TX-750 \ Corsair RM1000X Shift
Mouse Steelseries Sensei wireless \ Steelseries Sensei wireless
Keyboard Logitech K120 \ Wooting Two HE
Benchmark Scores Meh benchmarks.
WOW awesome naming, shame one of the others were not called IntelFall.

Take THAT AMD. I dont wanna hear the fanbois anymore.

Well Intel and Arm might be in the same boat so.

And OMG "The researchers "believe that networks that contain AMD" they believe ?. If this was found on Intel they would dare to say shit yet.
 
Joined
Jan 8, 2017
Messages
8,944 (3.36/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
I wonder if "RYZENFALL" was intended as "Ryze-and-fall". That would have been smart of them.
 
Joined
Dec 16, 2017
Messages
2,730 (1.18/day)
Location
Buenos Aires, Argentina
System Name System V
Processor AMD Ryzen 5 3600
Motherboard Asus Prime X570-P
Cooling Cooler Master Hyper 212 // a bunch of 120 mm Xigmatek 1500 RPM fans (2 ins, 3 outs)
Memory 2x8GB Ballistix Sport LT 3200 MHz (BLS8G4D32AESCK.M8FE) (CL16-18-18-36)
Video Card(s) Gigabyte AORUS Radeon RX 580 8 GB
Storage SHFS37A240G / DT01ACA200 / WD20EZRX / MKNSSDTR256GB-3DL / LG BH16NS40 / ST10000VN0008
Display(s) LG 22MP55 IPS Display
Case NZXT Source 210
Audio Device(s) Logitech G430 Headset
Power Supply Corsair CX650M
Mouse Microsoft Trackball Optical 1.0
Keyboard HP Vectra VE keyboard (Part # D4950-63004)
Software Whatever build of Windows 11 is being served in Dev channel at the time.
Benchmark Scores Corona 1.3: 3120620 r/s Cinebench R20: 3355 FireStrike: 12490 TimeSpy: 4624
Haha, for what reason? Have it caused anything for Intel except for its shitty communication?

Well, I originally just skimmed over the article. So, I though that for Intel something like this could have had negligible impact (except for the possible lawsuits), but AMD is a bit more vulnerable, because of the much lower market share and the company's more economically complicated situation.
Now, and considering that most of these vulnerabilities need certain uncommon conditions (special privileges and physical access), it doesn't seem to me that it could end up being a shitstorm, though it'd definitely be embarrassing...

Um, maybe you missed it but if you have access to update said bios even in windows, that would mean you already have root/admin... so wtf are you doing? Why even bother with a hack/flaw/bug whatever? Why not get to the business of stealing whatever the eff you are there for?

Maybe I could be waiting for some specific file to be transferred to the server? Or maybe I could be a creep and monitor all communications in and out?

Look at Equifax, the guys just sat down and held the doors open for themselves for a few months. What if someone did that with the NSA? Valuable data would definitely go through there, and there would be people very interested in getting it, no matter the cost. If that happened to the Pentagon's network... well, that could be really worrisome.
 
Last edited:
Joined
Oct 19, 2007
Messages
8,203 (1.36/day)
Processor Intel i9 9900K @5GHz w/ Corsair H150i Pro CPU AiO w/Corsair HD120 RBG fan
Motherboard Asus Z390 Maximus XI Code
Cooling 6x120mm Corsair HD120 RBG fans
Memory Corsair Vengeance RBG 2x8GB 3600MHz
Video Card(s) Asus RTX 3080Ti STRIX OC
Storage Samsung 970 EVO Plus 500GB , 970 EVO 1TB, Samsung 850 EVO 1TB SSD, 10TB Synology DS1621+ RAID5
Display(s) Corsair Xeneon 32" 32UHD144 4K
Case Corsair 570x RBG Tempered Glass
Audio Device(s) Onboard / Corsair Virtuoso XT Wireless RGB
Power Supply Corsair HX850w Platinum Series
Mouse Logitech G604s
Keyboard Corsair K70 Rapidfire
Software Windows 11 x64 Professional
Benchmark Scores Firestrike - 23520 Heaven - 3670
Haha, for what reason? Have it caused anything for Intel except for its shitty communication?




I'm not a researcher either, but I found it pretty easily. You should have done so, if you were really interested in the news. In fact, you are only an Intelboy.
Not hardly. Im not an "intelboy" i have owned both AMD and Intel. In fact, i got my feet wet with an AMD Athlon XP back in the day. Then a 3200+ after that and an AMD opteron after that.

I go where the performance is. Intel just happens to be that. My original comment in this thread was a stab at the AMD fanboys because of the intel controversy not too long ago and how "amd is so much better" (paraphrasing here) and now we turn around and AMD is on the end of the pitchfork. It's just ironic.

So before you try and call me a fanboy, maybe you should do some research on me before trying to start something. ;)
 
Joined
Apr 30, 2012
Messages
3,881 (0.89/day)
:roll::roll::roll:

^^Hey I recognize those 3 employees now.


The guy in the middle the co-founder Yaron Luk-Zilberman serves as the President at NineWells Capital Management.

NineWells Capital Management, LLC is a privately owned investment manager. The firm manages hedge funds for its clients. NineWells Capital Management is based in New York, New York

That might explain the AMDFlaws.com being registered to a New York number or more sinister as to why AMD wasn't notified in a timely manner.

Funny side note: at least for me. When you visit their site is says "not secure" in browser.
 
Joined
Oct 19, 2007
Messages
8,203 (1.36/day)
Processor Intel i9 9900K @5GHz w/ Corsair H150i Pro CPU AiO w/Corsair HD120 RBG fan
Motherboard Asus Z390 Maximus XI Code
Cooling 6x120mm Corsair HD120 RBG fans
Memory Corsair Vengeance RBG 2x8GB 3600MHz
Video Card(s) Asus RTX 3080Ti STRIX OC
Storage Samsung 970 EVO Plus 500GB , 970 EVO 1TB, Samsung 850 EVO 1TB SSD, 10TB Synology DS1621+ RAID5
Display(s) Corsair Xeneon 32" 32UHD144 4K
Case Corsair 570x RBG Tempered Glass
Audio Device(s) Onboard / Corsair Virtuoso XT Wireless RGB
Power Supply Corsair HX850w Platinum Series
Mouse Logitech G604s
Keyboard Corsair K70 Rapidfire
Software Windows 11 x64 Professional
Benchmark Scores Firestrike - 23520 Heaven - 3670
Joined
Dec 29, 2010
Messages
3,457 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
The guy in the middle the co-founder Yaron Luk-Zilberman serves as the President at NineWells Capital Management.



That might explain the AMDFlaws.com being registered to a New York number.

Funny side note: at least for me. When you visit their site is says "not secure" in browser.

Doh, says a lot doesn't it? Man, I cannot wait until the Feds and SEC get involved in this.
 
Joined
Dec 15, 2006
Messages
1,703 (0.27/day)
Location
Oshkosh, WI
System Name ChoreBoy
Processor 8700k Delided
Motherboard Gigabyte Z390 Master
Cooling 420mm Custom Loop
Memory CMK16GX4M2B3000C15 2x8GB @ 3000Mhz
Video Card(s) EVGA 1080 SC
Storage 1TB SX8200, 250GB 850 EVO, 250GB Barracuda
Display(s) Pixio PX329 and Dell E228WFP
Case Fractal R6
Audio Device(s) On-Board
Power Supply 1000w Corsair
Software Win 10 Pro
Benchmark Scores A million on everything....
Joined
Feb 18, 2017
Messages
688 (0.26/day)
Not hardly. Im not an "intelboy" i have owned both AMD and Intel. In fact, i got my feet wet with an AMD Athlon XP back in the day. Then a 3200+ after that and an AMD opteron after that.

I go where the performance is. Intel just happens to be that.


Than you should have owned a Zen before the 8600K, and replace the 8600K for a 2600X or 2700X.
 
Joined
Oct 19, 2007
Messages
8,203 (1.36/day)
Processor Intel i9 9900K @5GHz w/ Corsair H150i Pro CPU AiO w/Corsair HD120 RBG fan
Motherboard Asus Z390 Maximus XI Code
Cooling 6x120mm Corsair HD120 RBG fans
Memory Corsair Vengeance RBG 2x8GB 3600MHz
Video Card(s) Asus RTX 3080Ti STRIX OC
Storage Samsung 970 EVO Plus 500GB , 970 EVO 1TB, Samsung 850 EVO 1TB SSD, 10TB Synology DS1621+ RAID5
Display(s) Corsair Xeneon 32" 32UHD144 4K
Case Corsair 570x RBG Tempered Glass
Audio Device(s) Onboard / Corsair Virtuoso XT Wireless RGB
Power Supply Corsair HX850w Platinum Series
Mouse Logitech G604s
Keyboard Corsair K70 Rapidfire
Software Windows 11 x64 Professional
Benchmark Scores Firestrike - 23520 Heaven - 3670
WOW awesome naming, shame one of the others were not called IntelFall.
Wintelfell. Get it? :D

Than you should have owned a Zen before the 8600K, and replace the 8600K for a 2600X or 2700X.
Im sorry im not made of money and cant upgrade everytime the latest and greatest comes out like some folks can. I have a baby to think about. Guess that sort of logic is lost on the likes of you.

I get what is best for my money at the time of my upgrade. If I can afford to do a full upgrade path to AMD and they are superior, I will.
 
Joined
Feb 18, 2017
Messages
688 (0.26/day)
I get what is best for my money at the time of my upgrade. If I can afford to do a full upgrade path to AMD and they are superior, I will.

After your starting comment "Take THAT AMD. I dont wanna hear the fanbois anymore." I cannot take you serious. Sorry. GN.
 
Joined
Nov 4, 2005
Messages
11,691 (1.73/day)
System Name Compy 386
Processor 7800X3D
Motherboard Asus
Cooling Air for now.....
Memory 64 GB DDR5 6400Mhz
Video Card(s) 7900XTX 310 Merc
Storage Samsung 990 2TB, 2 SP 2TB SSDs and over 10TB spinning
Display(s) 56" Samsung 4K HDR
Audio Device(s) ATI HDMI
Mouse Logitech MX518
Keyboard Razer
Software A lot.
Benchmark Scores Its fast. Enough.
Take THAT AMD. I dont wanna hear the fanbois anymore.
Yeah, all code that requires physical access, admin rights, and could be prevented by using an operating system, specifically Windows to enact is terrible.

Also, I hear if you let a user take a hammer to AMD processors, they break... unlike Intel.
 
Top