Major Security Alert: AMD Issues Bulletin on Critical TPM Vulnerabilities
Key Insights:
AMD has recently released an important security bulletin concerning vulnerabilities found in its Trusted Platform Module (TPM) implementation. Although the identified flaws pose considerable risks to system security and reliability, remedies for AMD’s various CPU families have been accessible for several months. Users are urged to apply these updates promptly.
In a revelatory announcement, researchers from the Trusted Computing Group uncovered potential security issues in AMD’s TPM code. This prompted AMD to introduce new firmware and motherboard updates aimed at mitigating the vulnerabilities. Interestingly, while the updates are now public, the patched TPM code has been available for users to install for quite a few months.
The specifics of the vulnerabilities came to light after Intel researchers alerted the TCG Vulnerability Response Team about a possible out-of-bounds read flaw within AMD’s TPM 2.0 reference code. This security gap can be exploited by local attackers with elevated user permissions, allowing them to access sensitive firmware data or potentially disrupt the TPM’s functionality.
AMD’s engineers confirmed the existence of two significant vulnerabilities within their TPM implementation. The first, designated CVE-2026-6726, poses a risk of information leakage. It allows malicious individuals to extract credentials from a TPM-aware Certificate Authority, giving them the ability to create fraudulent TPM encryption keys or manipulate TPM-based attestation methods.
The second flaw, CVE-2026-6727, is identified as a timing side-channel vulnerability affecting decryption processes utilizing the RSA cryptosystem. This issue could enable attackers to decrypt encrypted information or forge TPM 2.0 attestation keys. Importantly, both vulnerabilities necessitate local exploits with privileged user access, suggesting that they aren’t an immediate threat to systems solely accessible via the internet.
Despite the circumstances, these weaknesses carry high severity scores on the CVSS scale, at 8.5 and 8.3 respectively. The ramifications are far-reaching, impacting a wide array of processors, including the Epyc 4004 and 4005 series, various embedded processors, and Ryzen desktop CPUs spanning from the 3000 to 9000 series, as well as Threadripper workstation processors.
AMD strongly advises users to implement the available Platform Initialization firmware updates that address both CVE-2026-6726 and CVE-2026-6727. For most processors, these fixes have been on hand since May, while Ryzen Embedded CPUs received their updates in July.
The Trusted Platform Module, first defined by the TCG in 2003, is a security-centric cryptoprocessor specification. The major TPM 2.0 implementation upgrade has been around since 2014, and it is now a mandatory system requirement for Windows 11, significantly enhancing security for the Windows ecosystem.
However, the recent discovery of these AMD vulnerabilities serves as a stark reminder that complete security remains an ongoing challenge, even in today’s TPM-equipped computing landscape.