sign up log in
Want to go ad-free? Find out how, here.

Researchers suggest throw away your computer if 'Sinkclose' flaw in AMD processors is exploited to run malware

Technology / news
Researchers suggest throw away your computer if 'Sinkclose' flaw in AMD processors is exploited to run malware
Source: AMD
AMD Epyc processors. Source: AMD

Did you think the Intel flaw that can permanently damage the chip giant's 13th and 14th Generation Core processors was bad? Its long standing rival, Advanced Micro Devices - AMD - didn't say "hold my beer" but they might as well because the company's chips have been shipping with the super bad Sinkclose bug for decades.

That bug was found by two researchers at security vendor IOActive, and affects "virtually all AMD chips dating back to 2006, or possibly even earlier," as Andy Greenberg at Wired, which was given first dibs on the story that broke at the legendary DEF CON hacking conference, wrote.

Going back that far in time means we're talking about hundreds of millions of processors, the little semiconductor brains of PCs.

How the Sinkclose bug works is pretty Deep Geek, but AMD chips have a System Management Mode (SMM) which has the highest privileges on a computer. 

What can you do with SinkClose then, if you're a malicious hacker-attacker?

Long story short, get into the SMM, and you can run malicious code that anti-viruses can't detect. That undetectable code has full access to all bits of the computer, which in an infosec context is as bad it gets.

Then it gets worse, because at that high level in the computer, in what's called the firmware which is used to start up the computer with certain settings, the code persists and is very hard to remove.

Wiping your computer and reinstalling the operating system won't clear the infection.

Should a computer become infected, the researchers suggest that the only practical thing to do is to throw it away. 

AMD has acknowledged the bug, saying it's a high severity one, and released a security bulletin with affected products and mitigation measures.

Luckily, it appears the researchers are the first to have discovered SinkClose.

What's more, it's not that easy to exploit either as it requires deep access to the computer system. This is no doubt why AMD has marked the bug as "high severity" and not "critical".

However, if some admittedly obsessive, hugely patient and clever researchers can find SinkClose and exploit it, there's some chance at least that threat actors will too. Particularly since it was presented at DEF CON to the hacker community.

Keep en eye out for updates in Windows with patches for SinkClose, in other words if your PC has an AMD chip inside.

We welcome your comments below. If you are not already registered, please register to comment.

Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.

4 Comments

Moved away from everything AMD years ago now, I run with Intel and Nvidia. Never liked the iPhone either, especially after it was hacked by Pegasus, go Samsung.

Up
2

Intel 7th Gen and NVidia here. This article made me look tho!

Up
2

I've more often than not bought AMD as a matter of performance vs cost. No loyalties here and I come from an IT background. Have upgraded our gaming PCs at home to 7800X3D with no regrets, AMD for the win this round.

Up
1

Thanks for the flag, helped me patch up some devices!

Up
0