AMD reveals vulnerabilities in their - 3C

Callum avatar
By Callum
at 2020-10-16T01:45

Table of Contents

因為全篇是英文,所以我就直接講結論了
各位要更新Ryzen Master 和Radeon驅動
我覺得這沒什麼大不了的
畢竟真正修不好的是Intel 的Spectre

AMD reveals vulnerabilities in their Ryzen Master and Radeon Software
AMD has updated its product security webpage to highlight two new software vulne
rabilities, which impact the company's Ryzen Master Software and Radeon Software
driver stack.

Within AMD's Radeon Software, Cisco Talos uncovered a vulnerability (called Esca
pe Handler) which allowed users to create a blue screen. Thankfully, this bug do
es not impact long-term system functionality and could be resolved by restarting
affected PCs. AMD believes that this bug cannot be used to gain access to confi
dential information. This bug has been addressed within AMD's latest Radeon Soft
ware driver release.

Within Ryzen Master, a researcher has uncovered a security vulnerability which a
llows authenticated users to gain access to system privileges. Thankfully, AMD b
elieves that this exploit cannot be used as a remote attack vector for affected
versions of Ryzen Master. AMD's latest Ryzen Master release has been patched to
address this vulnerability.

Details for both vulnerabilities are available below.



Escape Handler (CVE-2020-12933)
10/13/2020

Our ecosystem collaborator Cisco Talos has published a new potential vulnerabili
ty in AMD graphics drivers, which may result in a blue screen. The issue was add
ressed in Radeon™ Software Adrenalin 2020 Edition available here.

AMD believes that confidential information and long-term system functionality ar
e not impacted, and users can resolve the issue by restarting the computer.

A specially crafted D3DKMTEscape request can cause an out-of-bounds read in Wind
ows OS kernel memory area. This vulnerability can be triggered from a non-privil
eged account.

We thank the researchers for their ongoing collaboration and coordinated disclos
ure. More information on their research can be found on the Cisco Talos website.



AMD Ryzen Master™ Driver Vulnerability (CVE-2020-12928)
10/13/2020

A researcher has discovered a potential security vulnerability impacting AMD Ryz
en™ Master that may allow authenticated users to elevate from user to system pr
ivileges. AMD has released a mitigation in AMD Ryzen Master 2.2.0.1543. AMD beli
eves that the attack must come from a non-privileged process already running on
the system when the local user runs AMD Ryzen™ Master and that a remote attack
has not been demonstrated. The latest version of the software is available for d
ownload at https://www.amd.com/en/technologies/ryzen-master.

We thank the researcher for the ongoing collaboration and coordinated disclosure
.

AMD reveals vulnerabilities in their Ryzen Master and Radeon Software

Ryzen Master users should update to the latest version of Ryzen Master and Radeo
n GPU users should update their drivers to AMD's newest Radeon Software release.

--
Tags: 3C

All Comments

Candice avatar
By Candice
at 2020-10-18T08:50
ryzen-master 多了一個.
Ivy avatar
By Ivy
at 2020-10-20T02:57
Driver沒寫好 out of boundary然後bsod
Callum avatar
By Callum
at 2020-10-21T13:40
就bsod而已 其實沒什麼大不了
Dora avatar
By Dora
at 2020-10-24T07:53
有差嗎?BSOD是常態的說
Sierra Rose avatar
By Sierra Rose
at 2020-10-25T01:41
3700x+radeon VII已經很久沒遇到bsod了 最近有什麼
災情嗎?

爐石+CAD繪圖機

Andrew avatar
By Andrew
at 2020-10-16T00:24
感謝大家分享,我又重新配了一個菜單 CPU+主機版:華碩 PRIME B460M-A + 十代I5-10400【六核12緒】 更換原因:之前用Z490是因為搭665P有折價1300, 既然已經換SSD,就可以換主機版折扣了。 記憶體 ...

Intel下一代AlderLake確認LGA1700矩形PCB

Madame avatar
By Madame
at 2020-10-16T00:01
Videocardz洩露了Intel下一代Alder Lake桌上型CPU的第一張照片 圖片顯示Intel計劃對其第12代處理器系列進行重大更改,這些處理器將在全新的插槽和 平台上得到支援 目前為止Intel已正式確認計劃在2021年推出兩個全新的CPU系列。首先是針對Rocket Lake的LGA 1200 ...

EVGA為3080 FTW3 ULTRA發布450W BIOS

Gary avatar
By Gary
at 2020-10-16T00:01
RTX 3080 FTW3現在有了一個新的BIOS。BIOS將最大功率限制增加到450W 這是對顯示卡的重大升級,默認情況下顯示卡的電源限制為400W 但這款BIOS並不適用於遊戲玩家,它僅用於超頻,但並不能保證更高的性能。 3080 FTW3的最大TDP為450W,與ASUS RTX 3080 ROG ST ...

傳XFX將大部分AMD顯卡直接賣給大礦工

Ivy avatar
By Ivy
at 2020-10-16T00:01
雖然說在近期顯卡挖礦這件事情似乎已經自 2018 年初開始逐漸淡出一般用戶的視野中 畢竟以現在的數位貨幣幣價來看的確在沒有相當廉價的電力成本下 拿顯卡來進行挖礦的收益可能還無法打平過支出成本 但對於擁有相當廉價電力的大型礦工來說,目前為止拿顯卡挖礦確實還是有利可圖的。 根據中國博板堂得到的消息,在今年整個 ...

華碩B450F+RYZEN 5 3600XT手刀開搶

Dora avatar
By Dora
at 2020-10-16T00:00
原價屋出清XT便宜賣 活動商品: 華碩 ROG STRIX B450-F GAMING+AMD 3600XT 門當戶對! XT當3600賣. 有夠香~, $9860 史上最短命的銷售週期CPU  AMD XT 七月上市十月被取代 連A粉都不忍直視XT 當不存在的XT - ...