11 ms·
The RCE that AMD won't fix
- NullPrefix 8mo ago>Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts I love how they grouped man in the middle there
- deleted 8mo ago[deleted]
- rtpg 8mo agoThis is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediately own anyone with ATI graphics?
- hulitu 8mo ago> Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediately own anyone with ATI graphics? Some of us do not enable automatic updates (automatic updates are the peak of stupidity since Win98 era). And, when you sit in an airport, you don't update all your programs.
- Kodiack 8mo agoAutomatic updates are absolutely not peak stupidity. Most users’ devices would have nasty security vulnerabilities wide open for a much longer period of time without automatic updates.
- dbtablesorrows 8mo agoWho would connect to unknown person's hotspot? But it seems pretty trivial for some bad actor at local ISP.
- hpdigidrifter 8mo agoThis is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?
- dbtablesorrows 8mo agoAh I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.
- krater23 8mo agoAnd you have them in your laptop? Or just using your phone and don't own a laptop at all?
- ZiiS 8mo agoI would use my phone's 'hotspot' long before I tried random wifi on my laptop?
- zeendo 8mo agoAre you being willfully obtuse or do you actually believe that's true of everyone? There are so many reasons why someone might have a laptop in such a situation but not be able to use a hotspot on their phone - it's not even worth listing them.
- ZiiS 8mo agoThat isn't what this thread suggested; I was supporting plausibility of the GP's claim never to have used public Wifi because of good 4G; stating they could still have used a laptop in public. My wording was also explicit that this isn't always an option.
- ano-ther 8mo agoNot that this isn’t bad, doesn’t this only apply when an update is available? So you have to be on a shady hotspot, without VPN, AMD has recently published an update, and your update scheduler is timed to run. That would be a little less than “immediately own anyone with ATI”.
- pmontra 8mo agoIf somebody is MITMing a target person, they will respond positively to "update available?" calls from that person and then serve the tainted update. The article does not say what the frequency of auto update check is. Let's say one per day. If somebody is targeted it's one day away from RCE.
- thedanbob 8mo agoThe update check is HTTPS, only the files themselves are HTTP.
- pmontra 8mo agoI missed that, thanks!
- cestith 8mo agoTLS doesn’t mask the IP of the server. The updater probably isn’t using DNS over HTTPS. If I can determine that a user’s updater just hit the update check server, I can start impersonating the update server. That takes it out of the one day away territory, but it does allow an attacker to only have a malicious HTTP capture up and detectable during the actual attack window. Then, of course, if you’re also being their DNS server you can send them to the wrong update check server in the first place. I wonder if the updater validates the certificate.
- Ginden 8mo agoYou need only a device on network to spam DHCP messages with malware DNS. So you don't need "shady hotspot", only compromised device within network.
- ramon156 8mo agoYou can get arrested for this in my country, fun fact. I guess that's how you prevent anything, just make it illegal and the exploit becomes an unintended illegal feature, like occupying the low-freq radio signal.
- Tajnymag 8mo agoJust like burglary is illegal in every country on Earth, yet it still happens.
- bravetraveler 8mo agoBased on the policy (and my hat) I have to assume some business partner failed to maintain the 'ca-certificates' equivalent for Windows (or NTP) and was rewarded in their insane demand for plaintext. So easy to fix, just... why? My kingdom for an 's'. One of these policies are not like the others. Consider certificates and signatures before categorically turning a blind eye to MitM, please: you "let them in", AMD. Wow.
- arjie 8mo agoWhy even bother with WONTFIX? Turning on an nginx LetsEncrypt in front of it would have taken as long.
- testing12_12 8mo ago[dead]
- Dylan16807 8mo agoYes coincidence.
- jMyles 8mo agoIf this is true, it seems like a much more serious vulnerability than I was expecting when I clicked the link. And it's obviously an oversight; there is no reason to intentionally opt for http over https in this situation.
- Terr_ 8mo agoSo compromising one DNS lookup is sufficient, ex: 1. Home router compromised, DHCP/DNS settings changed. 2. Report a wrong (malicious) IP for ww2.ati.com. 3. For HTTP traffic, it snoops and looks for opportunities to inject a malicious binary. 4. HTTPS traffic is passed through unchanged. __________ If anyone still has their home-router using the default admin password, consider this a little wake-up call: Even if your new password is on a sticky-note, that's still a measurable improvement. The risks continue, though: * If the victim's router settings are safe, an attacker on the LAN may use DHCP spoofing to trick the target into using a different DNS server. * The attacker can set up an alternate network they control, and trick the user into connecting, like for a real coffee shop, or even a vague "Free Wifi."
- wiredpancake 8mo ago[dead]
- tptacek 8mo agoThey're not considering it not to be a vulnerability. They're simply saying it's outside the scope of their bug bounty program.
- Retr0id 8mo agoLooks like there's a serious security bug in their scope document.
- tptacek 8mo agoHow's that? What do you think the purpose of a bug bounty is? If you think it's "to eradicate all bugs", no, very no.
- JJJollyjim 8mo agoThis is the place they direct researchers to report bugs. If they don’t want to pay out for MITM, that’s fine, but they should still be taking out-of-scope reports seriously
- bravetraveler 8mo ago+1 Bounty aside, this deserves attention. I wouldn't want to award bounties for MitM either if I made it so easy. They closed the issue as 'out of scope'... with no mention of follow-up (or even the bounty we don't care about). I'm skeptical to say the least. Industry standard has been to ignore MitM or certificates/signatures, not everything.
- Retr0id 8mo agoI don't expect an unbounded scope but I do expect it to cover the big scary headline items like RCE. Additionally, this can be exploited without MitM if you combine with e.g. a DNS cache poisoning attack. And they can still fix it even if they're not willing to pay a bounty.
- 8mo ago
- bb88 8mo agoIt's not directly an RCE unto itself, it requires something else. A compromised DNS on the network, e.g. So no surprise they ignored it. Also, if AMD is getting overwhelmed with security reports (a la curl), it's also not surprising. Particularly if people are using AI to turn bug bounties into income. Lastly if it requires a compromised DNS server, someone would probably point out a much easier way to compromise the network rather than rely upon AMD driver installer.
- pixl97 8mo agoAs someone that works security, the whole "A compromised DNS on the network" would be a total excuse not to pay. The fact is allowing any type of unsigned update on HTTP is a security flaw in itself. >someone would probably point out a much easier way to compromise the networ No, not really. That's why every other application on the planet that does security of any kind uses either signed binaries or they use HTTPSONLY. Simply put allowing HTTP updates is insecure. The network should never be by default trusted by the user. What's even fucking dumber on AMDs part is this is just one BGP hijacking from a worldwide security incident.
- pooper 8mo ago> The fact is allowing any type of unsigned update on HTTP is a security flaw in itself. Reminds me about ten years or so ago when I was installing Debian or something and I noticed the URL for the apt install mirrors were http and not https. People helpfully pointed out this is a non issue because the updates are signed. Ok I guess but then why did Debian switch to https?
- kasabali 8mo ago> Ok I guess but then why did Debian switch to https? Because security people kept bullying them?
- rkeene2 8mo agoIt really just requires a network that doesn't use some kind of NAC since you can trivially do ARP poisoning of your target.
- b1temy 8mo agoWhile I don't like that the executable's update URL is using just plain HTTP, AMD does explicitly state that in their program that attacks requiring man-in-the-middle or physical access is out-of-scope. Whether you agree with whether this rule should be out-of-scope or not is a separate issue. What I'm more curious about is the presence of both a Development and Production URL for their XML files, and their use of a Development URL in production. While like the author said, even though the URL is using TLS/SSL so it's "safe", I would be curious to know if the executable URLs are the same in both XML files, and if not, I would perform binary diffing between those two executables. I imagine there might be some interesting differential there that might lead to a bug bounty. For example, maybe some developer debug tooling that is only present only in the development version but is not safe to use for production and could lead to exploitation, and since they seemed to use the Development URL in production for some reason...
- pixl97 8mo ago> is a separate issue. No, just no. This is not a separate issue. It is 100% the issue. Lets say I'm a nation state attacker with resources. I write up my exploit and then do a BGP hijack of whatever IPs the driver host resolves to. There you go, I compromised possibly millions of hosts all at once. You think anyone cares that this wasn't AMDs issue at this point?
- b1temy 8mo agoYou misunderstand. I already said I do not like that it is just using HTTP, and yes, it is problematic. What I am saying is that the issue the author reported and the issue that AMD considers man-in-the-middle attacks as out-of-scope, are two separate issues. If someone reports that a homeowner has the keys visibly on top of their mat in front of their front-door, and the homeowner replies that they do not consider intruders entering their home as a problem, these are two separate issues, with the latter having wider ramifications (since it would determine whether other methods and vectors of mitm attacks, besides the one the author of the post reported, are declared out-of-scope as well). But that doesn't mean the former issue is unimportant, it just means that it was already acknowledged, and the latter issue is what should be focused on (At least on AMD's side. It still presents a problem for users who disagree with AMD of it being out-of-scope).
- TacticalCoder 8mo ago> This means that a malicious attacker on your network, or a nation state that has access to your ISP can easily perform a MITM attack and replace the network response with any malicious executable of their choosing. http://www2.ati.com/... I'm blocking port 80 since forever so there's that. But now ati.com is going straight into my unbound DNS server's blocklist.
- nalekberov 8mo ago> This means that a malicious attacker on your network, or a nation state that has access to your ISP can easily perform a MITM attack and replace the network response with any malicious executable of their choosing. I am pretty sure, a nation state wanting to hack an individual's system has way more effective tools at their disposal.
- yunnpp 8mo agoPresumably, all Windows installations running on AMD are auto-executing this auto-update program.
- pixl97 8mo agoI guess one should keep their eyes out on the next big BGP hijack.
- Hizonner 8mo agoI am pretty sure nation states hire people smart enough to use whatever works. What the hell is more effective than getting root with a trivial MITM? Not only is it effective, it's stealthy, in that it doesn't out you. It's obviously possible to both find and exploit it without a huge investment, which means nobody knows you're a nation state when you use it. You don't have to risk burning any really arcane zero-days or any hard to replace back doors. Nation states are absolutely going to use things like that. And so is everybody else.
- userbinator 8mo ago...such as talking directly to AMD or even Microsoft, which is scarier as Windows Updates are signed, and as long as they can be convinced to sign the right thing, it'll look even more legit.
- digiown 8mo agoOne good thing we can say about Linux bundling all the drivers is that it obviates the need to run almost all of this type of low quality (if not outright spyware) driver management software. They are especially problematic because they can't be sandboxed easily like most other proprietary crap. For whatever reason, distro maintainers working for free seem a lot more competent with security than billion dollar hardware vendors
- Hikikomori 8mo agoYou don't really need to run these updaters on windows.
- aleph_minus_one 8mo ago> For whatever reason, distro maintainers working for free seem a lot more competent with security than billion dollar hardware vendors I don't believe that these billion dollar hardware vendors are really incompetent with security. It's rather that the distro maintainers do care quite a bit about security, while for these hardware vendors consider these security concerns to be of much smaller importance; for their business it is likely much more important to bring the next hardware generation to the market as fast as possible. In other words: distro maintainers and hardware vendors are simply interested in very different things and thus prioritize things very differently.
- da_chicken 8mo agoSure. New sales means new revenue. Maintenance and support is just overhead. It's shortsighted, but modern capitalism is more shortsighted than Mr. Magoo.
- lloeki 8mo agoIt's a cost vs benefit. As long as the cost of such blatant violation of security principles doesn't outweight the benefit of focusing on something else, nothing is done. https://www.legalexaminer.com/lestaffer/legal/gm-recall-defective-ignition-switch-saved-company-1/ https://www.legalexaminer.com/lestaffer/legal/gm-recall-defe... https://www.youtube.com/watch?v=IA2EBWFCULg https://www.youtube.com/watch?v=IA2EBWFCULg
- redox99 8mo agoWow, this is an extremely serious vulnerability. People writing it off because it requires MitM. There's always a MitM, the internet is basically a MitM.
- webstrand 8mo agoMitM isn't even necessary, a rogue DHCP server configuring a malicious DNS could attack this.
- kortilla 8mo agoThat is a form of MiTM. It’s just changing DNS to IP bindings rather than IP to MAC or prefix to ISP.
- burnt-resistor 8mo agoThat's still a MITM, albeit a LAN-local one. Non-LAN WAN isn't the total scope of MITMs.
- coip 8mo agoSpooky, this is not exposure if using Linux?
- zythyx 8mo agoAMD AutoUpdate terminal always pops up at midnight for me and then requires me to dismiss it. I've been meaning to uninstall this but always forget about it the next morning. Now I have good reason to block it entirely and go back to manual updates
- LilBytes 8mo agoOmg that's what it is. I've been looking for DAYS.
- sznio 8mo agoWhen I still used Windows that console window would show up and hang for hours. I'd finally close it when shutting down my PC, and it was guaranteed that the driver would be gone on the next boot and I'd need to install it again. It's the shittest autoupdater I had to ever deal with. It never actually managed to install an update.
- svespalec 8mo agoThis is unfortunate news but I'm not even surprised that they don't seem to care. Nice writeup.
- president_zippy 8mo agoMarking this as a WONTFIX should have gotten somebody fired at AMD. I find it hard to believe that at least one of their VPs doesn't frequent this site. I don't normally call for people to get fired from their jobs, but this is so disgusting to anyone who takes even a modicum of pride in their contribution to society. Surely, someone gets fired for dismissing a legitimate, easily exploited RCE using a simple plaintext HTTP MITM attack as a WONTFIX... Right???
- carefree-bob 8mo agoFrom the title, I thought this was going to be another one of those speculative execution information leakage bugs that are basically impossible to fix, but something this simple and easily fixable -- it's discouraging. Hopefully this decision is reversed. Also "Thank you for hacking our product" seems a bit unprofessional for someone engaging in responsible disclosure for a major security issue with your product.
- tgsovlerkhgsel 8mo ago"Thank you for hacking our product" sounds perfectly appropriate to me; it clearly uses "hacking" in the positive sense.
- Delk 8mo agoIt actually says "hacking on one of our programs", which makes it even more obvious that it's using the word closer to the positive traditional hacker culture sense. I'm sure that still looks unprofessional to some people, just like any jargon that isn't corporatese does.
- carefree-bob 8mo agoI could have been giving this an uncharitable reading.
- burnt-resistor 8mo agoThanks for this, author. No https:// and no cryptographic signature nor checksum that I can see. This makes it almost trivial for any nation-state to inject malware into targeted machines. I removed AMD auto-update functionality from Windows boxen. (And I won't install anything similar on Linux.) And, besides, the Windows auto-update or check process hangs with a blank console window regularly. Such trashy software ruins the OOBE of everything else. Small details attention zen philosophy and all that.
- yellow_lead 8mo agoMany people don't worry about connecting to random wifi anymore, but users of AMD still have to
- dbtablesorrows 8mo agoI do usually worry - because DNS spoofing is still possible and we are one step (eg: a compromised certificate) away from being pwned. But yeah one shouldn't have to worry.
- raffraffraff 8mo agoHow the hell is it possible that they're still using the ATI domain and HTTP 2026? They acquired ATI 20 fucking years ago. It really makes you wonder what level of dysfunction is actually possible inside a company. 30k employees and they can't get one of them to hook up certbot, and add an 's' to the software.
- Habgdnv 8mo agoI was in the shop for new PC today and decided on 9950x3d but I don't know how I opened HN just before the checkout and now I am a happy owner of intel 14900!
- YouAreWRONGtoo 8mo ago[dead]
- jimrandomh 8mo agoIf this is as described, it's a pretty major failure of security-vulnerability report triage, and rises to the level where security departments at major corporations will be having meetings about whether they want to ban AMD hardware from their organizations entirely, or only ban the AMD update application. If this had gone the "brand name and a scored CVE" route, it would probably have gotten a news cycle. It might still get a news cycle. The threat model here is that compromised or malicious wifi hotspots (and ISPs) exist that will monitor all unencrypted traffic, look for anything being downloaded that's an executable, and inject malware into it. That would compromise a machine that ran this updater even if the malware wasn't specifically looking for this AMD driver vulnerability, and would have already compromised a lot of laptops in the past.
- r1ch 8mo agoAnyone can request a CVE, this is sadly the most likely path towards getting it fixed.
- krater23 8mo agoAuto Update is EVERYTIME a RCE. When the software checks a signature, you just need the key. And the delivering enterprise have the key. EVERYTIME. Don't understand why most people mean auto updating software would in any way create more security. It just creates more attack vectors for every software that has a auto updater.
- dns_snek 8mo agoRemote Code Execution (RCE) is a type of vulnerability. Intentionally running code from a developer you trust is not a vulnerability. An auto-update mechanism only becomes an RCE if it allows unauthorized third parties to execute code on your machine by failing to verify that the code comes from a legitimate source. > you just need the key Secrecy of cryptographic keys is the basis of all cryptography we use. There's no "just", you need the key and you don't have it.
- deleted 8mo ago[deleted]
- dns_snek 8mo agoCan anyone rationalize this decision? Sure technically this is outside the stated scope however the severity of this vulnerability is immediately obvious, which should trigger some alarm bells that the scope needs to be reconsidered. If they lose just one customer over this they're losing more than the minimum $500 bounty. They also signal to the world that they care more about some scope document than actually improving security, discouraging future hackers from engaging with their program. This would be a high severity vulnerability so even paying out $500 for a low severity would be a bit of a disgrace. What's the business case for screwing someone out of a bounty on a technicality?
- Avamander 8mo agoHonestly, even if it were in scope, just them getting paid is a bit odd given how AMD has been made aware of this multiple times over the years.
- Avamander 8mo agoThis is why I've blocked all HTTP traffic outgoing from my machines. A lot of people have brought this up over the years: https://www.reddit.com/r/AMDHelp/comments/ysqvsv/amd_autoupdateexe/mltu3z2/ https://www.reddit.com/r/AMDHelp/comments/ysqvsv/amd_autoupd... (I'm fairly sure I have even mentioned AMD doing this on HN in the past.) AMD is also not the only one. Gigabyte, ASUS, many other autoupdaters and installers fail without HTTP access. I couldn't even set up my HomePod without allowing it to fetch HTTP resources. From my own perspective allowing unencrypted outgoing HTTP is a clear indication of problematic software. Even unencrypted (but maybe signed) CDN connections are at minimum a privacy leak. Potentially it's even a way for a MITM to exploit the HTTP stack, some content parser or the application's own handling. TLS stacks are a significantly harder target in comparison.
- bflesch 8mo agoAFAIK a lot of linux packet repositories are http-only as well. Convenient for tracking what package versions have been installed on a certain system.
- arghwhat 8mo agoThey usually support both, but important to note that HTTPS is only used for privacy. Package managers generally enforce authenticity through signed indexes and (directly or indirectly) signed packages, although be skeptical when dealing with new/minor package managers as they could have gotten this wrong.
- Avamander 8mo agoReducing the benefit of HTTPS to only privacy is dishonest. The difference in attack surface exposed to a MITM is drastic, TLS leaves so little available for any attacker to play with.
- mldbk 8mo agoMITM usually will not work in case of pkg managers, since packages are signed. But still, attacker can learn what kind of software is installed on target. So I believe that HTTPS for privacy in case of linux package managers are fair enough.
- Someone 8mo agoFTA: “Therefore I will have to close the report as out of scope” and “05/02/2026 - Report Closed as wont fix/out of scope” I think it’s a bit early to say “won’t fix”. AMD only said that it was out of scope for the channel used to report it (I don’t know what that was, but it likely is a bug bounty program) and it’s one day after the issue was reported to them.
- TekMol 8mo agoEven though the software might have been written by AMD, I think there is at least one more party to blame. Who has put that software on the PC in the first place? Was it the manufacturer? Or was it Microsoft via Windows?
- moktonar 8mo agoBugdoors, bugdoors everywhere.. The fact that they refuse to fix is the sketchiest part, and also they should be held accountable for things like this IMO
- zbyforgotp 8mo agoWhat is the root cause of this? It is said that AMD is hardware company and neglects software - but recently they issued lots of declarations of becoming software firs now.
- throw0101a 8mo agoMeta: somewhat surprised that they're still using ati.com. ATI was acquired back in 2006: * https://en.wikipedia.org/wiki/ATI_Technologies https://en.wikipedia.org/wiki/ATI_Technologies
- akabul0us 8mo ago[dead]
- satiric 8mo agoHere it is on archive.org, since the original was taken down (hey, the cat's out of the bag now): https://web.archive.org/web/20260205155934/https://mrbruh.com/amd/ https://web.archive.org/web/20260205155934/https://mrbruh.co...
- Brownaxios 8mo ago[dead]