The RCE that AMD wouldn't fix
A security researcher discovered a Remote Code Execution vulnerability in AMD's AutoUpdate software caused by insecure HTTP update downloads. Although initially dismissed by AMD's bug bounty program, the company agreed to review the report after the issue gained public attention.
Why it matters
Demonstrates the risks of insecure software update mechanisms and the role of public disclosure in corporate security accountability.
After being interrupted multiple times by an annoying console window that would pop up periodically on my new gaming PC, I managed to track the offending executable down to AMD's AutoUpdate software.
The article provides a technical account of a security flaw and the subsequent corporate response.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in