Home Hardware Tutorial Hardware News \'Sinkclose\' vulnerability discovered in post-2006 AMD chips could pose a critical threat to data security

\'Sinkclose\' vulnerability discovered in post-2006 AMD chips could pose a critical threat to data security

Aug 11, 2024 pm 09:33 PM
cpu amd laptop ryzen test Notebook review reviews tests reports netbook TClose

'Sinkclose' vulnerability discovered in post-2006 AMD chips could pose a critical threat to data security

Severe security vulnerabilities rarely occur, but they are a major inconvenience when they do. The 0.0.0.0 Day exploit is one recent example of the same. This latest one is dubbed Sinkclose, and it has been discovered in AMD processors dating back to 2006. The flaw allows malicious actors to gain unprecedented access to a computer system, potentially enabling data theft, surveillance, and system control.

The vulnerability exploits a weakness in the System Management Mode (SMM) of AMD chips, a privileged area typically reserved for critical firmware operationssuch as power management, thermal control, hardware initialization, and security functions. By manipulating a feature called TClose, attackers can bypass security safeguards and execute their own code at the SMM level, granting them near-total control over the system.

The implications? Possibly quite serious. Malware installed through Sinkclose can be very difficult to remove, likely leading to a complete system replacement in worst-case scenarios. If users pop the CPU out of an infected system and use it with new components, the new system will get infected. Those with malicious intent can even go to the lengths of reselling such CPUs and potentially gain control of multiple systems over time.

AMD has acknowledged the issue and released patches for its EPYC datacenter and Ryzen PC products, with additional mitigations for embedded systems (used in automation and transportation) on the way. However, the company also zoomed in to discuss the complexity of exploiting the vulnerability. In a statement to WIRED, AMD compared the Sinkclose technique to a method for accessing a bank's safe-deposit boxes after already bypassing its alarms, the guards, and vault door.

As tech evolves, so do the threats targeting it. To protect against Sinkclose, users should prioritize installing available patches from exclusively AMD and their system manufacturers. While the risk might seem low for the average user, the potential consequences are severe enough to warrant immediate action. We're talking data theft, system takeover or even espionage, where nation-state actors could exploit the vulnerability to spy on individuals or organizations.

If you want to take a look at all AMD products affected by Sinkclose, the company has them listed here.

'Sinkclose' vulnerability discovered in post-2006 AMD chips could pose a critical threat to data security

The above is the detailed content of \'Sinkclose\' vulnerability discovered in post-2006 AMD chips could pose a critical threat to data security. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1663
14
PHP Tutorial
1266
29
C# Tutorial
1239
24
Huawei Watch GT 5 smartwatch gets update with new features Huawei Watch GT 5 smartwatch gets update with new features Oct 03, 2024 am 06:25 AM

Huawei is rolling out software version 5.0.0.100(C00M01) for the Watch GT 5 and the Watch GT 5 Prosmartwatchesglobally. These two smartwatches recently launched in Europe, with the standard model arriving as the company’s cheapest model. This Harmony

Tekken\'s Colonel Sanders dream fried by KFC Tekken\'s Colonel Sanders dream fried by KFC Oct 02, 2024 am 06:07 AM

Katsuhiro Harada, the Tekken series director, once seriously tried to bring Colonel Sanders into the iconic fighting game. In an interview with TheGamer, Harada revealed that he pitched the idea to KFC Japan, hoping to add the fast-food legend as a g

Cybertruck FSD reviews praise quick lane switching and full-screen visualizations Cybertruck FSD reviews praise quick lane switching and full-screen visualizations Oct 01, 2024 am 06:16 AM

Tesla is rolling out the latest Full Self-Driving (Supervised) version 12.5.5 and with it comes the promised Cybertruck FSD option at long last, ten months after the pickup went on sale with the feature included in the Foundation Series trim price. F

Garmin releases Adventure Racing activity improvements for multiple smartwatches via new update Garmin releases Adventure Racing activity improvements for multiple smartwatches via new update Oct 01, 2024 am 06:40 AM

Garmin is ending the month with a new set of stable updates for its latest high-end smartwatches. To recap, the company released System Software 11.64 to combat high battery drain across the Enduro 3, Fenix E and Fenix 8 (curr. $1,099.99 on Amazon).

New Xiaomi Mijia Graphene Oil Heater with HyperOS arrives New Xiaomi Mijia Graphene Oil Heater with HyperOS arrives Oct 02, 2024 pm 09:02 PM

Xiaomi will shortly launch the Mijia Graphene Oil Heater in China. The company recently ran a successful crowdfunding campaign for the smart home product, hosted on its Youpin platform. According to the page, the device has already started to ship to

First look: Leaked unboxing video of upcoming Anker Zolo 4-port 140W wall charger with display First look: Leaked unboxing video of upcoming Anker Zolo 4-port 140W wall charger with display Oct 01, 2024 am 06:32 AM

Earlier in September 2024, Anker's Zolo 140W charger was leaked, and it was a big deal since it was the first-ever wall charger with a display from the company. Now, a new unboxing video from Xiao Li TV on YouTube gives us a first-hand look at the hi

Samsung Galaxy Z Fold Special Edition revealed to land in late October as conflicting name emerges Samsung Galaxy Z Fold Special Edition revealed to land in late October as conflicting name emerges Oct 01, 2024 am 06:21 AM

The launch of Samsung's long-awaited 'Special Edition' foldable has taken another twist. In recent weeks, rumours about the so-called Galaxy Z Fold Special Edition went rather quiet. Instead, the focus has shifted to the Galaxy S25 series, including

Manjaro 24.1 \'Xahea\' launches with KDE Plasma 6.1.5, VirtualBox 7.1, and more Manjaro 24.1 \'Xahea\' launches with KDE Plasma 6.1.5, VirtualBox 7.1, and more Oct 02, 2024 am 06:06 AM

With a history of over one decade, Manjaro is regarded as one of the most user-friendly Linux distros suitable for both beginners and power users, being easy to install and use. Mostly developed in Austria, Germany, and France, this Arch-based distro

See all articles