AMD patched a series of security holes in the graphics driver for Windows 10
Among these are dozens of vulnerabilities rated high risk.
"After a comprehensive analysis of AMD Escape commands, we found a set of weaknesses in several APIs. These weaknesses make the system vulnerable to privilege escalation, denial-of-service attacks and denial-of-service attacks. services, disclose information, bypass KASLR, or write arbitrary code to memory," AMD said.
These vulnerabilities were discovered by independent security researchers Ori Nimron and driverThru_BoB 9th, CyberArk Labs' Eran Shimony and Apple Media Products RedTeam's Lucas Bouillot.
The full list of patched bugs is as follows:
- Ori Nimron (@orinimron123): CVE-2020-12892, CVE-2020-12893, CVE-2020-12894, CVE-2020-12895, CVE-2020-12897, CVE-2020-12898, CVE-2020-12899, CVE -2020-12900, CVE-2020-12901, CVE-2020-12902, CVE-2020-12903, CVE-2020-12904, CVE-2020-12905, CVE-2020-12963, CVE-2020-12964, CVE-2020 -12980, CVE-2020-12981, CVE-2020-12982, CVE-2020-12983, CVE-2020-12986, CVE-2020-12987
- Eran Shimony, CyberArk Labs: CVE-2020-12892
- Lucas Bouillot, Apple Media Products RedTeam: CVE-2020-12929
- driverThru_BoB 9th: CVE-2020-12960
This week, AMD also patched medium and high-level vulnerabilities affecting AMD EPYC Gen 1st, 2nd, and 3rd processors for servers. These vulnerabilities lead to attacks of arbitrary code execution, SPI ROM protection bypass, integrity compromise, denial of service, and information disclosure attacks.
AMD says that it has partnered with Google, Microsoft, and Oracle to comprehensively test vulnerabilities in AMD Platform Security Processor (PSP), AMD System Management Unit (SMU), AMD Secure Encrypted Virtualization (SEV), and platform components other platform.
In early October, AMD also had to issue a warning about their chip's performance loss when running Windows 11. By the end of October, the performance reduction problem was fixed in Windows 11 update KB5006746.
You should read it
- Microsoft silently updated Windows 10 to patch 2 serious security holes
- McAfee software has a vulnerability that allows hackers to run code with system privileges on Windows
- New version of Firefox patched some additional security flaws
- Google launched Chrome 33, patched 7 new security bugs
- Detect 2 serious security holes in the Zoom application
- Internet Explorer has vulnerabilities, unused users are still hacked
- Cisco security equipment is targeted at DoS attacks through an old vulnerability
- How to fix BlueKeep security error for Windows 2003, Windows XP, Windows 7, Windows Server 2008
- More than 40 Windows drivers contain dangerous privilege escalation vulnerabilities
- Apple patched a total of 43 security bugs for Mac OS X
- Detecting a series of vulnerabilities can help hackers disable metal detectors at airports
- Top 30 serious security holes are being exploited by hackers the most