Zen and the Art of Microcode Hacking - Google Bug Hunters
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
Fig. 1. The EntrySign vulnerability logo (CCO) Today we are releasing the full details of EntrySign, the AMD Zen microcode signature validation vulnerability which we initially disclosed last month. In this post, we first discuss the background of what microcode is, why microcode patches exist, why the integrity of microcode is important for security, and how AMD attempts to prevent tampering with microcode. Next, we focus on the microcode patch signature validation process and explain in detail the vulnerability present (using CMAC as a hash function). Finally, we discuss how to use some…
saved by
related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Zenbleedlock.cmpxchg8b.com
- A shallow dive into formal verificationvitalik.eth.limo
- Meltdown (security vulnerability) - Wikipediaen.wikipedia.org
- Discovering cryptographic weaknesses with Claude \ Anthropicanthropic.com
- A bug fix in the 8086 microprocessor, revealed in the die's siliconrighto.com
- Introducing MAI-Cyber-1-Flash inside MDASH | Microsoft AImicrosoft.ai
- Ken Shirriff's blogrighto.com
- Reading privileged memory with a side-channel - Project Zerogoogleprojectzero.blogspot.com
- Themes from Real World Crypto 2022 - The Trail of Bits Blogblog.trailofbits.com
- Intel Management Engineen.wikipedia.org
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com