Executive brief
A vulnerability in the AMD Secure Processor (ASP), a dedicated security chip within AMD processors, could allow an attacker with low-level access to bypass certain privilege checks. By exploiting this flaw, an attacker could write unauthorized data to the processor's functions, potentially causing system instability or compromising the integrity of secure operations. This could impact the overall reliability and security of servers or workstations using affected AMD hardware.
Technical details
The AMD Secure Processor (ASP) suffers from an improper privilege management vulnerability (CWE-274). The flaw exists in how the ASP handles function inputs, failing to adequately verify that the requesting entity has the necessary permissions before performing write operations. An attacker with network access and low privileges (PR:L) can provide input values to specific functions to successfully write data. This unauthorized write capability can lead to a loss of integrity or availability of the secure environment. AMD has addressed this in security bulletin AMD-SB-6027.
Affected products
- AMD Secure Processor (ASP)
Timeline
- 2026-05-15: disclosed: Initial NVD publication date
- 2026-05-15: advisory: AMD Security Bulletin AMD-SB-6027 released