A dangerous vulnerability that has existed for 18 years threatens millions of AMD Ryzen and EPYC CPUs
The new vulnerability is called 'Sinkclose'. Hackers need to have deep access to computers or servers that operate on AMD processing systems to exploit this vulnerability. They can use bootkit malware - a type of malicious code that is difficult to detect and difficult to patch, to exploit vulnerabilities, thereby penetrating and controlling the system. Hackers will then install malware that is difficult to detect and can even persist even after reinstalling the operating system.
Although only recently reported, Sinkclose appears to have existed in many of AMD's CPU product lines, from desktops, workstations, servers to embedded devices and graphics solutions, for 18 years. pass without being detected.
AMD was notified about this vulnerability 10 months ago. The company has confirmed the existence of the Sinkclose vulnerability and has released patches for EPYC and Ryzen CPUs. The company also provides software and firmware patches to minimize the impact of the vulnerability.
To patch the vulnerability to ensure the safety of your system, AMD recommends that users update the latest BIOS.
You should read it
- Apple releases iOS 14.4.2, iOS 12.5.2, and watchOS 7.3.3 updates that patch the critical zero-day vulnerability
- Critical Vulnerability Discovered in 3 WordPress Plugins, Affects 84,000 Websites
- Detected critical zero-day vulnerability on Adobe Reader
- Discovered a new zero-day vulnerability on macOS that allows attackers to run commands remotely
- Detecting zero-day vulnerability in the Dropbox 10 Windows app, users pay attention!
- Detecting a new Linux vulnerability allows hackers to gain control of the VPN connection
- Detecting an 8-year-old security flaw, affecting 150 HP printer models
- Network security guide before vulnerability 196
May be interested
- There is a serious security vulnerability that has existed for 18 years in AMD processors, but it is not too worryingsecurity researchers at ioactive have discovered a serious vulnerability that exists in nearly two dozen amd-branded cpu models.
- How to choose AMD CPUin the past few years, amd has released some great cpus. names like ryzen 3 and ryzen 5 suggest the idea that they might be equivalent to intel i3 and intel i5.
- AMD changed its mind, continuing to support Ryzen 4000 CPUs on B450 and X470 motherboardsthe biggest beneficiary is the user when ryzen 1 series motherboard can support up to 4 generations of cpu, like someone else
- Specter V2 vulnerability re-appears to attack Intel, Arm CPUs, AMD chips are not affectedsecurity research team vusec and intel have just released a notice of a dangerous remote execution vulnerability of the specter class, known as branch history injection or bhi.
- Top cheap gaming CPUs worth buying in 2023thanks to recent cpu lineups from both intel and amd, gamers on a tight budget have more options. amd's zen 3 architecture in ryzen 5000 cpus and intel's 12th gen core cpus has helped create powerful gaming chips without breaking the bank.
- Microsoft admits a new zero-day vulnerability threatens millions of Windows usersaccording to microsoft, this new zero-day vulnerability affects all versions of windows from windows 7 to windows 10 and corresponding versions of windows server.
- Ryzen Threadripper 3980X, AMD's new CPU revealed with 48 cores, 96 threadsrecently, information about the ryzen threadripper 3980x 48 core 96 threads, one of two ryzen threadripper cpus 3rd generation amd is about to launch has been leaked.
- AMD released a firmware update for Specter to fix the vulnerability on the CPUamd has allowed users to update the firmware for ryzen and epyc this week.
- Warning of dangerous Spring4Shell vulnerability, there are signs of scanning and exploitingspring has just released an urgent update to patch the spring4shell remote code execution zero-day vulnerability. information about this vulnerability was leaked on the internet before the patch was released.
- Detecting serious security flaws that exist for more than 19 years on WinRAR, can affect 500 million userson february 20, security experts at check point discovered a very dangerous vulnerability that existed inside the library of winrar code over the past 19 years, allowing hackers to broadcast it. a malicious code and plugged into a user's computer to perform malicious purposes.