Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Fractal Design Pop Air RGB Black TG review
Palit GeForce GTX 1630 4GB Dual review
FSP Dagger Pro (850W PSU) review
Razer Leviathan V2 gaming soundbar review
Guru3D NVMe Thermal Test - the heatsink vs. performance
EnGenius ECW220S 2x2 Cloud Access Point review
Alphacool Eisbaer Aurora HPE 360 LCS cooler review
Noctua NH-D12L CPU Cooler Review
Silicon Power XPOWER XS70 1TB NVMe SSD Review
Hyte Y60 chassis review

New Downloads
Prime95 download version 30.9 build 1
Intel ARC graphics Driver Download Version: 30.0.101.1743
AMD Radeon Software Adrenalin 22.6.1 WHQL driver download
GeForce 516.59 WHQL driver download
Media Player Classic - Home Cinema v1.9.22 Download
AMD Chipset Drivers Download v4.06.10.651
CrystalDiskInfo 8.17 Download
AMD Radeon Software Adrenalin 22.6.1 Windows 7 driver download
ReShade download v5.2.2
HWiNFO Download v7.26


New Forum Topics
ASUS ROG Swift OLED PG48 UQ specs disclose 4K organic EL display compatible with 138Hz / 0.1ms. 516.59 - Clean Version [3rd-Party Driver] Amernime Zone Radeon Insight 22.5.1 WHQL Driver Pack (Released) Slow PC after 512.95 Nvidia shows signs ... 3060ti vs 6700xt a year later MSI AB / RTSS development news thread AMD Might Release and Add Ryzen 5 5600X3D, Ryzen 9 5900X3D (X3D) procs Extreme 4-Way Sli Tuning Should I force "Rebar" in games that aren't on Nvidia's approved list?




Guru3D.com » News » AMD fixed a vulnerability in its chipset drivers that let non-administrators get passwords

AMD fixed a vulnerability in its chipset drivers that let non-administrators get passwords

by Hilbert Hagedoorn on: 09/21/2021 03:42 PM | source: | 7 comment(s)
AMD fixed a vulnerability in its chipset drivers that let non-administrators get passwords

First off, the vulnerability was fixed in AMD's newest PSP and chipset drivers (download here), which AMD recommends updating. Kyriakos Economou, a security researcher and co-founder of ZeroPeril, uncovered the flaw and promptly contacted AMD, working closely with the red team to patch it.

This vulnerability allows obtaining information of all kinds, including credentials of users with administrative privileges to escalate privileges or hashes that allow network access, and even exceeding mitigations of different vulnerabilities to later exploit them. Economou said this regarding the new vulnerability:

During our tests we were able to filter out multiple gigabytes of uninitialized physical pages when reserving and continuously release blocks of 100 reservations until the system fails to return a buffer of contiguous physical pages.

The content on these physical pages ranged from kernel objects to arbitrary pool addresses that served to bypass mitigations for vulnerabilities such as KASLR, and they even had registry key mappings of \ Registry \ Machine \ SAM containing NTLM hashes of authentication credentials. that could be used in subsequent attacks.

For example, this technique can be used to steal credentials from a user with administrative privileges or used in the "pass-the-hash" style to gain access within a network.

The PSP (Platform Security Processor) drivers should be updated to version 5.17.0.0 via Windows Update, and the chipset drivers should be updated to version 3.08.17.735 or newer, which already includes the PSP update that resolves this vulnerability. No BIOS updates are required.







« Intel 6th patent infringement case, China may restrict the sale of its CPUs. · AMD fixed a vulnerability in its chipset drivers that let non-administrators get passwords · Corsair Announces the Release of the M65 RGB ULTRA Gaming Mice »

Related Stories

AMD Fixes More Ryzen Issues with New BIOS Firmware Microcode - 03/31/2017 04:18 PM
Performance keeps on improving in games with Ryzen, that would be the generic message AMD is evengalizing on a new Blog post. It seems that AMD has made good progress on the software side of things. Y...

AMD fixes R9 Fury X Whining Noises - 07/02/2015 08:38 AM
One of the smaller problems of the AMD Radeon R9 Fury X is that the cooler is making some noises alongside a tiny bit of whine. We noted that in our review already. However AMD seems to have tackled ...


2 pages 1 2


KissSh0t
Senior Member



Posts: 11219
Joined: 2011-10-22

#5948614 Posted on: 09/22/2021 01:11 PM
Interesting driver date. Instead of getting it early, you machine simply moved into the future.


That's why I'm finding this new article so strange... the driver version for the PSP was released a little while ago :X

Exodite
Senior Member



Posts: 2061
Joined: 2006-09-28

#5948728 Posted on: 09/22/2021 09:40 PM
Interesting driver date. Instead of getting it early, you machine simply moved into the future.

Not everyone uses the messed-up US date format. :p

Here's the ISO date, for comparison:


2 pages 1 2


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2022