Executive brief
A security flaw in an AMD KVM (Kernel-based Virtual Machine) component allows unauthorized access to sensitive cryptographic keys. An attacker who knows the specific web address of the key download service can download these keys without needing a password or any form of identification. This could compromise the confidentiality of encrypted data or virtual machine environments managed by the affected system.
Technical details
A missing authentication vulnerability (CWE-306) exists in the AMD KVM key download endpoint. The flaw allows an unauthenticated remote attacker to access and retrieve sensitive cryptographic keys by directly accessing the exposed URL. While the attack requires knowledge of the specific endpoint URL, no prior authentication or special privileges are required to execute the request. Successful exploitation results in a loss of confidentiality for the keys managed by this component. AMD has addressed this in security bulletin AMD-SB-9023.
Affected products
- AMD KVM Key Download Endpoint
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory: NVD publication date