• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

13 Major Vulnerabilities Discovered in AMD Zen Architecture, Including Backdoors

Joined
Apr 16, 2010
Messages
3,456 (0.68/day)
Location
Portugal
System Name LenovoⓇ ThinkPad™ T430
Processor IntelⓇ Core™ i5-3210M processor (2 cores, 2.50GHz, 3MB cache), Intel Turbo Boost™ 2.0 (3.10GHz), HT™
Motherboard Lenovo 2344 (Mobile Intel QM77 Express Chipset)
Cooling Single-pipe heatsink + Delta fan
Memory 2x 8GB KingstonⓇ HyperX™ Impact 2133MHz DDR3L SO-DIMM
Video Card(s) Intel HD Graphics™ 4000 (GPU clk: 1100MHz, vRAM clk: 1066MHz)
Storage SamsungⓇ 860 EVO mSATA (250GB) + 850 EVO (500GB) SATA
Display(s) 14.0" (355mm) HD (1366x768) color, anti-glare, LED backlight, 200 nits, 16:9 aspect ratio, 300:1 co
Case ThinkPad Roll Cage (one-piece magnesium frame)
Audio Device(s) HD Audio, RealtekⓇ ALC3202 codec, DolbyⓇ Advanced Audio™ v2 / stereo speakers, 1W x 2
Power Supply ThinkPad 65W AC Adapter + ThinkPad Battery 70++ (9-cell)
Mouse TrackPointⓇ pointing device + UltraNav™, wide touchpad below keyboard + ThinkLight™
Keyboard 6-row, 84-key, ThinkVantage button, spill-resistant, multimedia Fn keys, LED backlight (PT Layout)
Software MicrosoftⓇ WindowsⓇ 10 x86-64 (22H2)
Subjectively speaking, compared to Meltdown attack page, this one has waaaay too many AMD logos. Without reading the text, one might actually mistake it for an ad! Count me up holding a pitchfork if Intel turned out to have a hand in this.

Objectively speaking, smear campaign or no, a vulnerability is a vulnerability. I'm personally quite illiterate on this matter so I'll defer judgement until "for dummies-"style security expert blog posts and articles start popping up.
If proved true, the usual applies.
Common sense running programs and visiting the internet, make sure you have backups (cold ones preferably), patch as soon as possible.
When it can survive a reinstall it's still a big issue. If these flaws are confirmed they are fairly signifigant.

As I said earlier, 2018 is going to be a rough year for processor security...
Only if it's embedded in firmware, but to reach that far, so much needs to be compromised to begin with...
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
We have just received a report from a company called CTS Labs claiming there are potential security vulnerabilities related to certain of our processors. We are actively investigating and analyzing its findings. This company was previously unknown to AMD and we find it unusual for a security firm to publish its research to the press without providing a reasonable amount of time for the company to investigate and address its findings. At AMD, security is a top priority and we are continually working to ensure the safety of our users as potential new risks arise. We will update this blog as news develops.
http://ir.amd.com/news-releases/news-release-details/view-our-corner-street-0
 
Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
I kinda agree with AMD's point of view in that news release. If it is truly the case, releasing the CVE's without telling the vendor first seems counterproductive. I wouldn't go as far as to say this is fishy, but like I said earlier, once it ends up on a more official channel, I'll be more inclined to believe it.
 
Joined
Nov 3, 2013
Messages
2,141 (0.56/day)
Location
Serbia
Processor Ryzen 3600
Motherboard X570 I Aorus Pro
Cooling Deepcool AG400
Memory HyperX Fury 2 x 8GB 3200 CL16
Video Card(s) RX 470 Nitro+ 4GB
Storage SX8200 Pro 512 / NV2 512
Display(s) 24G2U
Case NR200P
Power Supply Ion SFX 650
Mouse G703
Keyboard Keychron V1 (Akko Matcha Green) / Apex m500 (gateron milky yellow)
Software W10
I like how @FordGT90Concept put more effort in investigating than the TPU editorial that published the article.

On a different note, stock actually rose. Not by much, and it looks stable at the moment, but nonetheless.


1.png
 
Joined
Mar 18, 2008
Messages
5,717 (0.97/day)
System Name Virtual Reality / Bioinformatics
Processor Undead CPU
Motherboard Undead TUF X99
Cooling Noctua NH-D15
Memory GSkill 128GB DDR4-3000
Video Card(s) EVGA RTX 3090 FTW3 Ultra
Storage Samsung 960 Pro 1TB + 860 EVO 2TB + WD Black 5TB
Display(s) 32'' 4K Dell
Case Fractal Design R5
Audio Device(s) BOSE 2.0
Power Supply Seasonic 850watt
Mouse Logitech Master MX
Keyboard Corsair K70 Cherry MX Blue
VR HMD HTC Vive + Oculus Quest 2
Software Windows 10 P
I like how @FordGT90Concept put more effort in investigating than the TPU editorial that published the article.

On a different note, stock actually rose. Not by much, and it looks stable at the moment, but nonetheless.


View attachment 98284

Agree. This entire thing feels like a huge PR scam from the Isreal based “security” firm.
 
Joined
Feb 17, 2017
Messages
852 (0.33/day)
Location
Italy
Processor i7 2600K
Motherboard Asus P8Z68-V PRO/Gen 3
Cooling ZeroTherm FZ120
Memory G.Skill Ripjaws 4x4GB DDR3
Video Card(s) MSI GTX 1060 6G Gaming X
Storage Samsung 830 Pro 256GB + WD Caviar Blue 1TB
Display(s) Samsung PX2370 + Acer AL1717
Case Antec 1200 v1
Audio Device(s) aune x1s
Power Supply Enermax Modu87+ 800W
Mouse Logitech G403
Keyboard Qpad MK80
There always be flaws, there are 2 types, deliberate ones and unnoticed ones....

And we always know that when we're talking about AMD, it's ALWAYS the second. Unlike other companies... :mad:
 

the54thvoid

Intoxicated Moderator
Staff member
Joined
Dec 14, 2009
Messages
12,450 (2.38/day)
Location
Glasgow - home of formal profanity
Processor Ryzen 7800X3D
Motherboard MSI MAG Mortar B650 (wifi)
Cooling be quiet! Dark Rock Pro 4
Memory 32GB Kingston Fury
Video Card(s) Gainward RTX4070ti
Storage Seagate FireCuda 530 M.2 1TB / Samsumg 960 Pro M.2 512Gb
Display(s) LG 32" 165Hz 1440p GSYNC
Case Asus Prime AP201
Audio Device(s) On Board
Power Supply be quiet! Pure POwer M12 850w Gold (ATX3.0)
Software W10
Agree. This entire thing feels like a huge PR scam from the Isreal based “security” firm.

No, it's all salty tears from us. :rolleyes:

And yes, too many people trying to be 'no, this is a big thing' when really, it's not such a biggie given the practicality of the process involved in the security issue. And really, it's too glossy to be anything other than a negative PR campaign, NOT a bona fide security issue notice (like how Google played it's role last year with along NDA). This is threat PR. Only the naive folk here can't see that.
 
Low quality post by Konceptz
Joined
Sep 23, 2008
Messages
294 (0.05/day)
Location
Richmond, VA
Processor i7-14700k
Motherboard MSI Z790 Carbon Wifi
Cooling DeepCool LS720
Memory 32gb GSkill DDR5-6400 CL32 Trident Z5
Video Card(s) Intel ARC A770 LE
Storage 990 Pro 1tb, 980 Pro 512gb, WD black 4tb
Display(s) 3 x HP EliteDisplay E273
Case Corsair 5000D Airflow
Power Supply Corsair RM850x
Mouse Logitec MK520
Keyboard Logitec MK520
Software Win 11 Pro
Benchmark Scores Cinebench R23 Multi 35805
Wonder how much Intel paid for this?:laugh:
 
Joined
Jul 18, 2017
Messages
575 (0.23/day)
The double standard is real. Let's jump the gun and defame the researchers because this is AMD and not Intel. Hell, the AMD defense force has yet to provide actual evidence to discredit each of those findings but somehow someway found a way to link this to Intel. This AMD circlejerk culture, even though it's a vocal minority, has to stop.
 
Joined
Feb 17, 2017
Messages
852 (0.33/day)
Location
Italy
Processor i7 2600K
Motherboard Asus P8Z68-V PRO/Gen 3
Cooling ZeroTherm FZ120
Memory G.Skill Ripjaws 4x4GB DDR3
Video Card(s) MSI GTX 1060 6G Gaming X
Storage Samsung 830 Pro 256GB + WD Caviar Blue 1TB
Display(s) Samsung PX2370 + Acer AL1717
Case Antec 1200 v1
Audio Device(s) aune x1s
Power Supply Enermax Modu87+ 800W
Mouse Logitech G403
Keyboard Qpad MK80
Joined
Sep 23, 2008
Messages
294 (0.05/day)
Location
Richmond, VA
Processor i7-14700k
Motherboard MSI Z790 Carbon Wifi
Cooling DeepCool LS720
Memory 32gb GSkill DDR5-6400 CL32 Trident Z5
Video Card(s) Intel ARC A770 LE
Storage 990 Pro 1tb, 980 Pro 512gb, WD black 4tb
Display(s) 3 x HP EliteDisplay E273
Case Corsair 5000D Airflow
Power Supply Corsair RM850x
Mouse Logitec MK520
Keyboard Logitec MK520
Software Win 11 Pro
Benchmark Scores Cinebench R23 Multi 35805
The double standard is real. Let's jump the gun and defame the researchers because this is AMD and not Intel. Hell, the AMD defense force has yet to provide actual evidence to discredit each of those findings but somehow someway found a way to link this to Intel. This AMD circlejerk culture, even though it's a vocal minority, has to stop.

Any evidence to credit said researchers? Ford pointed out many points that back up the smear campaign theory...that surprisingly is shared by a LOT of people across the web. Don't let my avatar fool you, my alliance is purely to price/performance ratio.
 
Joined
Mar 10, 2010
Messages
11,878 (2.30/day)
Location
Manchester uk
System Name RyzenGtEvo/ Asus strix scar II
Processor Amd R5 5900X/ Intel 8750H
Motherboard Crosshair hero8 impact/Asus
Cooling 360EK extreme rad+ 360$EK slim all push, cpu ek suprim Gpu full cover all EK
Memory Corsair Vengeance Rgb pro 3600cas14 16Gb in four sticks./16Gb/16GB
Video Card(s) Powercolour RX7900XT Reference/Rtx 2060
Storage Silicon power 2TB nvme/8Tb external/1Tb samsung Evo nvme 2Tb sata ssd/1Tb nvme
Display(s) Samsung UAE28"850R 4k freesync.dell shiter
Case Lianli 011 dynamic/strix scar2
Audio Device(s) Xfi creative 7.1 on board ,Yamaha dts av setup, corsair void pro headset
Power Supply corsair 1200Hxi/Asus stock
Mouse Roccat Kova/ Logitech G wireless
Keyboard Roccat Aimo 120
VR HMD Oculus rift
Software Win 10 Pro
Benchmark Scores 8726 vega 3dmark timespy/ laptop Timespy 6506
Wow did'nt see this coming :rolleyes::D

the brassy-ballsy-ness and general bling of this new security firm is amazeballs, their in the wrong game regardless ,they should have definately been a PR company, they have skills.
Even the numbers, 13 vulnerabillities found,wow unlucky for someo_O but a few listed , should'nt it read like the ten commandments plus , not like a supervillan squad.

And I'm loving the balanced views personally(genuinely and not sarcastic), yes there is a bit of salt ,why not , opinions can get that way but i thought this thread would be much worse, might taint my purchasing options but well see yet, It's not like there are options after all ,power-pc maybe?? or a new chinese developed chip er no:D
 
Last edited:
Joined
Feb 17, 2017
Messages
852 (0.33/day)
Location
Italy
Processor i7 2600K
Motherboard Asus P8Z68-V PRO/Gen 3
Cooling ZeroTherm FZ120
Memory G.Skill Ripjaws 4x4GB DDR3
Video Card(s) MSI GTX 1060 6G Gaming X
Storage Samsung 830 Pro 256GB + WD Caviar Blue 1TB
Display(s) Samsung PX2370 + Acer AL1717
Case Antec 1200 v1
Audio Device(s) aune x1s
Power Supply Enermax Modu87+ 800W
Mouse Logitech G403
Keyboard Qpad MK80

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,259 (4.63/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
Let's jump the gun and defame the researchers because this is AMD and not Intel.
The "researchers" jumped the gun. AMD hasn't even had time yet to reproduce them for verification purposes.

When Specter and Meltdown went public, it was huge news because despite having six months to work on it, they weren't even close to fixing it. Even if one of these 13 ends up being legit, it most likely could have been quietly fixed without any fanfare. In this case, everything the "researchers" did was about maximizing fanfare. That should concern everyone. I hope this doesn't become the new norm but it could.
 
Last edited:
Joined
Apr 10, 2013
Messages
302 (0.07/day)
Location
Michigan, USA
Processor AMD 1700X
Motherboard Crosshair VI Hero
Memory F4-3200C14D-16GFX
Video Card(s) GTX 1070
Storage 960 Pro
Display(s) PG279Q
Case HAF X
Power Supply Silencer MK III 850
Mouse Logitech G700s
Keyboard Logitech G105
Software Windows 10
AMD provided us with the following statement: "We have just received a report from a company called CTS Labs claiming there are potential security vulnerabilities related to certain of our processors. We are actively investigating and analyzing its findings.
So AMD wasn't able to discredit the claims after 36 hours of research. Probably some verified vulnerabilities then as they only take a short time to verify. Ugly mess how it was released; a serious security company would WANT the mfg to fix the problems not benefit by exposure. AMD will fix.
 
Joined
Mar 18, 2008
Messages
5,717 (0.97/day)
System Name Virtual Reality / Bioinformatics
Processor Undead CPU
Motherboard Undead TUF X99
Cooling Noctua NH-D15
Memory GSkill 128GB DDR4-3000
Video Card(s) EVGA RTX 3090 FTW3 Ultra
Storage Samsung 960 Pro 1TB + 860 EVO 2TB + WD Black 5TB
Display(s) 32'' 4K Dell
Case Fractal Design R5
Audio Device(s) BOSE 2.0
Power Supply Seasonic 850watt
Mouse Logitech Master MX
Keyboard Corsair K70 Cherry MX Blue
VR HMD HTC Vive + Oculus Quest 2
Software Windows 10 P
Power of Reddit. Entire video footage of their “security firm” is all just green screened. Someone over reddit found all the available stock background this firm used for their video.

I am not just calling this BS now, this is market manipulation and scam. Shame on tech sites that took it and run with it WITHOUT doing their own homework. GT90 did way more research than the editors here

A5E4ACFE-84CC-4997-94AE-460A5C7C918F.jpeg
 
Joined
Feb 17, 2017
Messages
852 (0.33/day)
Location
Italy
Processor i7 2600K
Motherboard Asus P8Z68-V PRO/Gen 3
Cooling ZeroTherm FZ120
Memory G.Skill Ripjaws 4x4GB DDR3
Video Card(s) MSI GTX 1060 6G Gaming X
Storage Samsung 830 Pro 256GB + WD Caviar Blue 1TB
Display(s) Samsung PX2370 + Acer AL1717
Case Antec 1200 v1
Audio Device(s) aune x1s
Power Supply Enermax Modu87+ 800W
Mouse Logitech G403
Keyboard Qpad MK80
Power of Reddit. Entire video footage of their “security firm” is all just green screened. Someone over reddit found all the available stock background this firm used for their video.

I am not just calling this BS now, this is market manipulation and scam. Shame on tech sites that took it and run with it WITHOUT doing their own homework. GT90 did way more research than the editors here

Wow, you're soo keen man
 

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,259 (4.63/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
So AMD wasn't able to discredit the claims after 36 hours of research. Probably some verified vulnerabilities then as they only take a short time to verify. Ugly mess how it was released; a serious security company would WANT the mfg to fix the problems not benefit by exposure. AMD will fix.
Not really. If all they provided is a white paper, AMD has to author its own tools then they have to run said tools against a variety of hardware. If the tools indicate some truth to the claims, they have to dig deeper and find out why. The why indicates whether or not it is something that needs to be fixed or not, and how. This process will likely take a month.
 
Joined
Jul 29, 2015
Messages
19 (0.01/day)
Processor I7 4770k
Cooling Corsair H100i
Memory 16 gigs
Video Card(s) MSI 390x 8gb
Storage 1tb SSD, 2 512gb in raid 0
Display(s) ASUS MG279Q Black 27" IPS 144Hz
Power Supply 1000w
Mouse Death Adder
Keyboard Microsoft Gaming keyboard thingy
Power of Reddit. Entire video footage of their “security firm” is all just green screened. Someone over reddit found all the available stock background this firm used for their video.

I am not just calling this BS now, this is market manipulation and scam. Shame on tech sites that took it and run with it WITHOUT doing their own homework. GT90 did way more research than the editors here

View attachment 98286

I'm upgrading to Zen+ after seeing this. Good bye i7, wonder if Intel is behind this or some former crypto miners looking for a quick buck manipulating AMD stocks.
 
Joined
Feb 17, 2017
Messages
852 (0.33/day)
Location
Italy
Processor i7 2600K
Motherboard Asus P8Z68-V PRO/Gen 3
Cooling ZeroTherm FZ120
Memory G.Skill Ripjaws 4x4GB DDR3
Video Card(s) MSI GTX 1060 6G Gaming X
Storage Samsung 830 Pro 256GB + WD Caviar Blue 1TB
Display(s) Samsung PX2370 + Acer AL1717
Case Antec 1200 v1
Audio Device(s) aune x1s
Power Supply Enermax Modu87+ 800W
Mouse Logitech G403
Keyboard Qpad MK80
I'm upgrading to Zen+ after seeing this. Good bye i7, wonder if Intel is behind this or some former crypto miners looking for a quick buck manipulating AMD stocks.

Intel, and also nvidia, are most definitely behind this man, get rid of your i7, just do it...
 
Joined
Apr 10, 2013
Messages
302 (0.07/day)
Location
Michigan, USA
Processor AMD 1700X
Motherboard Crosshair VI Hero
Memory F4-3200C14D-16GFX
Video Card(s) GTX 1070
Storage 960 Pro
Display(s) PG279Q
Case HAF X
Power Supply Silencer MK III 850
Mouse Logitech G700s
Keyboard Logitech G105
Software Windows 10
They provided instructions on how to recreate the issues 'found'. ;)
Yes. And google images and stutterstock added those green screen backgrounds 6 hours ago. Even the discredits are discredited... what a world!

This just got a mention on CNBC so watch that stock now that someone knows.
 
Joined
Oct 28, 2012
Messages
1,159 (0.28/day)
Processor AMD Ryzen 3700x
Motherboard asus ROG Strix B-350I Gaming
Cooling Deepcool LS520 SE
Memory crucial ballistix 32Gb DDR4
Video Card(s) RTX 3070 FE
Storage WD sn550 1To/WD ssd sata 1To /WD black sn750 1To/Seagate 2To/WD book 4 To back-up
Display(s) LG GL850
Case Dan A4 H2O
Audio Device(s) sennheiser HD58X
Power Supply Corsair SF600
Mouse MX master 3
Keyboard Master Key Mx
Software win 11 pro
(I know that motherboard isn't exactly a reference, but I'm curious to see how thing are going to evolve from there, dan guido and trail of bits are apparently not on the shady side.)
https://motherboard.vice.com/en_us/...ssor-ryzen-epyc-vulnerabilities-and-backdoors
" All 13 vulnerabilities are exploitable, according to Dan Guido, the founder of security firm Trail of Bits, whose researchers reviewed the flaws and exploit code before publication last week.
“Each of them works as described,” Guido told me in a phone call.

It’s important to note that all these vulnerabilities require hackers to get on the computers and gain administrative privileges some other way first, such as with a phishing attack that tricks the victim into running a malicious application, according to the CTS researchers and Guido.

This means that they are “second stage” vulnerabilities, which would allow attackers to move from computer to computer inside the same network, or install malware directly inside the processor that can’t get detected by security software. This would allow an attacker to spy on the target without detection."

So apparently those guys send a detailed document to trails of bits, a week before but choosed to alert AMD just 24h before. (How nice of them).
According to this guy the flaws are real:

 
Last edited:
Top