Researchers from IOActive have discovered a critical vulnerability in AMD processors that allows hackers to implant virtually undetectable malware. The issue affects millions of computers and servers worldwide, reports Wired.

The vulnerability, named Sinkclose, has been found in the System Management Mode (SMM) of AMD processors. This mode has high privileges and is intended for carrying out critical system functions. Malicious actors can exploit Sinkclose to inject malware deep into the firmware layers by altering the SMM configuration, making it nearly impossible to detect and remove.
Enrique Nissim and Krzysztof Okupski from IOActive, who discovered the vulnerability, plan to provide detailed insights about it at the upcoming hackers conference Defcon tomorrow. According to them, Sinkclose affects almost all AMD processors released since 2006, and possibly even earlier.
Researchers warn that while hackers need a certain level of access to an AMD-based computer or server to exploit the vulnerability, Sinkclose will then allow them to implant malicious code even deeper. On most tested systems where the Platform Secure Boot security feature is implemented incorrectly, a virus installed through Sinkclose will be nearly impossible to detect and remove, even after reinstalling the operating system.
"Imagine that hackers from the intelligence services or others want to embed themselves in your system. Even if you completely wipe the hard drive, the virus will still remain," says Okupski. He adds that the only way to remove such a virus is to physically connect to the computer's memory using an SPI Flash programmer and thoroughly scan it. "In the worst-case scenario, you might just have to throw away the computer," summarizes Nissim.
In a statement to Wired, AMD acknowledged IOActive's discovery, thanking the researchers and stating that it has already released fixes for EPYC and Ryzen processors, with patches for embedded systems coming soon. However, AMD did not disclose details on how exactly the Sinkclose vulnerability will be addressed and for which devices.
At the same time, AMD emphasizes the complexity of exploiting this vulnerability, as an attacker must have access to the operating system's kernel. However, Nissim and Okupski argue that for experienced hackers, gaining such access is not a problem due to the regularly emerging bugs in Windows and Linux.
Researchers warn that after the presentation at Defcon, even though detailed information about the exploit will not be published, experienced hackers may deduce how the technology works, so users are advised to install AMD patches as soon as they become available.
Sources:
Source: 3dnews.ru
