Description

A newly discovered vulnerability, dubbed SinkClose, poses a severe threat to nearly all AMD processors. This critical flaw allows attackers with kernel-level access to bypass system defenses and install persistent, virtually undetectable malware. The vulnerability, tracked as CVE-2023-31315, exploits a weakness in the System Management Mode (SMM) of AMD CPUs. SMM is a highly privileged area responsible for low-level system functions, making it an attractive target for malicious actors. By manipulating SMM settings, attackers can embed malware directly into the system's firmware, rendering it invisible to traditional security measures. While AMD has released patches for its EPYC and Ryzen desktop/mobile CPUs, concerns remain about the potential for widespread exploitation. The nature of the attack, requiring kernel-level access, might hinder its immediate impact. However, given the increasing sophistication of cyber threats, including the use of vulnerable drivers and zero-day exploits, the risk cannot be ignored.