- Joined
- Dec 19, 2005
- Messages
- 17,863
“"Is this fix effective, or can it be bypassed via a downgrade attack?" asked Demi Marie Obenour, a software developer for Invisible Things on the same security mailing list. She suggested that although exploitation is likely limited to highly privileged users and software, the bug could be used to undo super-low-level system security protections.
"Since microcode loading can (hopefully!) only be done in ring 0 and SVM root mode, this means that one needs OS kernel access to perform an exploit. However, if an attacker could load arbitrary microcode, they could compromise SMM, SEV-SNP, and DRTM, so this is still pretty bad."
Hey, worse things can happen. ®”
Source: https://www.theregister.com/2025/01/23/asus_amd_processor_fix/
"Since microcode loading can (hopefully!) only be done in ring 0 and SVM root mode, this means that one needs OS kernel access to perform an exploit. However, if an attacker could load arbitrary microcode, they could compromise SMM, SEV-SNP, and DRTM, so this is still pretty bad."
Hey, worse things can happen. ®”
Source: https://www.theregister.com/2025/01/23/asus_amd_processor_fix/