New AMD SinkClose flaw helps install nearly undetectable malware
ID: 7defa795-b50f-5eb7-99ce-d14a3aafa172
STIX ID: report--7defa795-b50f-5eb7-99ce-d14a3aafa172
Feed Name: Bleeping Computer
Threat Score
AMD's SinkClose (CVE-2023-31315) is a high-severity CPU vulnerability impacting many generations of EPYC, Ryzen, and Threadripper processors that allows an attacker with kernel (Ring 0) privileges to escalate to Ring -2 (System Management Mode), potentially installing persistent, nearly undetectable malware; AMD has released mitigations for many CPUs, but exploitation requires prior kernel access and detection/remediation is difficult without direct SPI flash inspection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
