AMD disclosed two high-severity vulnerabilities in its Trusted Platform Module 2.0 reference implementation, affecting a wide range of Epyc, Ryzen, Threadripper, and embedded processors. Firmware updates fixing the flaws have been available for months. The issues, reported through the Trusted Computing Group after discovery by Intel researchers, involve an out-of-bounds read and a timing side-channel in RSA decryption. Both require local, privileged access, limiting exposure for internet-only attack scenarios. One flaw can leak credentials and compromise TPM-based attestation, while the other may enable decryption of protected data. AMD urges users and administrators to apply the latest Platform Initialization firmware updates distributed by motherboard and system vendors.
This update represents a notable development in the Ai sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.