This is an AMD CPU that is prone to hacking: the infection doesn’t go away even though the OS is reinstalled

Sayangnya Tidak Semua CPU AMD Yang Rentan Ini Mendapatkan Update Keamanan

AThe threat to hardware security is increasing. This time, a serious threat was found on AMD processors which turned out to be vulnerable to attacks that could exploit security weaknesses since 2006. The discovery of AMD CPUs that are prone to being hacked shocked the world of technology and brings its own concerns for users and companies who rely on AMD processors in their daily operations.

Security flaws on AMD processors: “Sinkclose”

Researchers from IOActive recently discovered a weakness called “sinkclose” on AMD processors. This weakness allows the infected computer to run the code without being detected in the AMD Ryzen system management mode. This means, malicious code can be executed without being hindered by checking in Windows, BIOS, or UEFI. This issue was first exhibited at the Defcon Security Conference, attracting the attention of security experts around the world.

The serious impact of the “sinkclose” weakness

Once the system is compromised, the computer can be infected with a bootkit capable of avoiding conventional security tools, including antivirus software and Windows built-in protection. Even more worrying, this infection can even survive even if the user reinstalls the operating system in full. In some extreme cases, Enrique Nissim, the researcher involved in the invention, stated that “you have to basically throw your computer away,” underscores how difficult it is to remove this infection from the affected system.

Even more worrying, this infection can even survive even if the user reinstalls the operating system in full.

AMD’s response to security weaknesses

AMD has been informed of this weakness and stated that they have released mitigation options for Ryzen-based computers as well as industrial data center machines. They also promised to immediately update the embedded AMD hardware, such as APUs in game consoles.

List of affected AMD products

A complete list of AMD products affected by the weakness of SinkClose includes a chip that is long with the Ryzen 3000 series from 2019. All products in this list will receive an update to close the security hole. However, there is a difference between this list and a report published by Wired, which states that this weakness lies in the chips produced since 2006. Most of the chips, of course, have gone far past the official support period—and, fairly, perhaps not many are still actively used. However, the number of machines affected, both personal and industrial, remains very large, with hundreds of thousands of machines that are likely to still operate and possibly running important infrastructure.

Here is a table containing a list of AMD CPUs affected by the “sinkclose” weakness based on available information:

CPU generationCPU series/modelRelease year
AMD Ryzen 3000 SeriesRyzen 3 3100, Ryzen 3 3300x, Ryzen 5 3500, Ryzen 5 3600, Ryzen 7 3700x, Ryzen 7 3800x, Ryzen 9 3900x, Ryzen 9 3950x2019
AMD Ryzen 2000 SeriesRyzen 3 2300X, Ryzen 5 2600, Ryzen 7 2700, Ryzen 7 2700X, Ryzen 5 2400G, Ryzen 3 2200G2018
AMD Ryzen 1000 SeriesRyzen 3 1200, Ryzen 5 1600, Ryzen 7 1800x, Ryzen 5 1400, Ryzen 3 1300x, Ryzen 7 1700x, Ryzen 5 1500x2017
AMD FX SeriesFX-4300, FX-6300, FX-8320, FX-8350, FX-95902012
AMD Athlon SeriesAthlon 200GE, Athlon 220GE, Athlon 240GE2018
AMD Phenom II SeriesPhenom II X2, Phenom II X3, Phenom II X4, Phenom II X62009-2012
AMD Opteron SeriesOpteron 2300, Opteron 2400, Opteron 4100, Opteron 4200, Opteron 6200, Opteron 63002006-2012

Note: This list includes some examples of CPUs that may be affected. Many CPUs produced by AMD from 2006 to 2019 are most likely affected by the weakness of “sinkclose”.

If you are using one of the CPUs listed above, it is advisable to immediately check if there are any firmware or BIOS updates available to address this weakness.

Why is “sinkclose” hard to exploit?

The good news is that this weakness is not easily exploited, at least as far as we know today. The researchers gave AMD time to issue patches before they fully explained this weakness. To be exploited, the program must have kernel-level access to the system to be able to inject code into the boot sequence before the OS runs. (The researchers say that Microsoft and its OEM partners should immediately issue an update that patches this weakness on the current system.)

Risk of future attacks

The bad news, vulnerabilities at the kernel level, although technically complex and often fixed by Microsoft or other companies, is quite common. This is a type of weakness that is highly sought after by the country’s hacker team and industrial espionage agent because it is very strong and can be exploited on many systems.

What should the user do?

For users who are still using AMD processors from previous years, it is important to immediately update their systems to the latest available BIOS or UEFI versions. If updates are not available for older processors, considering upgrading hardware to newer versions could be a wise move to reduce risk.

For companies that rely on infrastructure supported by AMD processors, additional mitigation measures may be needed, including improving security surveillance and implementing a more stringent monitoring system to detect suspicious activity at the pre-boot level.

Why is hardware security so important?

Along with the increasingly complex computer hardware, hardware security is becoming increasingly crucial. The processor is the brain of the computer, and if there is a weakness at this level, the entire system can be threatened. In addition, attacks on hardware are often more difficult to detect and overcome compared to attacks on software. Therefore, ensuring that the hardware remains safe is an important step in maintaining the overall security of the system.

The long-term impact of this weakness

The weakness found in AMD processors is not only a problem for current users, but also has long-term implications. With so many processors no longer supported by official updates, there is a big risk that this weakness will continue to be exploited in the future, especially on systems that still use old hardware. This could have a negative impact on critical sectors, including important infrastructure that may still use old hardware for reasons of cost or stability.

influence on public trust

The discovery of this security weakness also has the potential to damage public confidence in AMD. Although all tech companies are sure to face security issues over time, the scale and scope of these weaknesses raises serious questions about how companies handle the safety of their products in the long run. Users and companies may be more careful in choosing processors in the future, especially in the context of increasing security needs.

Conclusion

The weakness of the “sinkclose” found in AMD processors is a reminder of the importance of updating the hardware and software periodically to protect the system from security threats. Although AMD has taken steps to address this problem, the fact is that many older processors may never get updates, leaving them vulnerable to future attacks. For users, it is important to stay alert and take proactive steps to protect their systems.


FAQ

What is the “sinkclose” weakness? The weakness of “SinkClose” is the security defect found in AMD processors that allows malicious code execution in system management mode (System Management Mode) without being detected by the operating system, BIOS, or UEFI.

Which AMD processors are affected by this weakness? The affected AMD processors include chips that are the same as the Ryzen 3000 series from 2019 to processors produced since 2006.

Can this weakness be exploited easily? No, this weakness is not easy to exploit because it requires kernel level access to the system to inject code into the boot order before the OS runs.

What to do if I use the affected AMD processor? Users are advised to immediately update the system to the latest available BIOS or UEFI versions. If an update is not available, consider upgrading the hardware to a newer version.

Has AMD already released an update to overcome this weakness? Yes, AMD has released mitigation options for Ryzen-based computers and industrial data center machines, as well as pledging to update embedded hardware such as APUs in game consoles.


Reference: Discovery of “sinkclose” weakness was reported by researchers from IOActive and presented at the DEFCON Security Conference.

Baca Juga

Back to top button

Adblock Detected

LidahTekno.com is supported by Google Adsense advertising to provide content for you.Please consider disabling AdBlocker or adding us to your whitelist so we can continue providing the best technology information and tips.Thank you for your support!