A critical security vulnerability has been identified in the firmware of the Trusted Platform Module (TPM) used in many processors from AMD and Intel. The flaw affects systems relying on the fTPM 2.0 reference code supplied by the Trusted Computing Group (TCG), which both companies incorporate into their BIOS versions. This component forms the root of trust for servers, desktop PCs, and notebooks, storing cryptographic keys essential for verifying system integrity and enabling features such as Windows BitLocker encryption. The vulnerabilities, designated as CVE-2026-6726 and CVE-2026-6727, have been rated highly severe with scores of 8.5 and 8.3 respectively under the Common Vulnerability Scoring System (CVSS). These flaws could allow attackers to manipulate the TPM, potentially compromising the entire system's security. However, exploiting these issues requires local access with elevated privileges, making them less of a concern for individual users than for corporate environments where devices might be more vulnerable to targeted attacks. CVE-2026-6727 involves a side-channel attack that exploits timing differences to extract secrets from the TPM. Attackers can use specially crafted software to send numerous commands to the coprocessor and measure the time taken for responses. By analyzing variations in response times, attackers can infer information about the cryptographic operations being performed, specifically filling blocks using the RSA-OAEP encryption method. Correct and incorrect fill values produce different response times, allowing attackers to deduce sensitive data. CVE-2026-6726 undermines the verification process of stored cryptographic keys. Under certain conditions, the TPM fails to invalidate discarded keys properly, allowing attackers to present a new forged key at the same address as a legitimate one. This enables deep manipulation of the system, potentially allowing unauthorized access and control over the device. AMD has confirmed that all desktop, notebook, and embedded processors based on the Zen architecture, including models ranging from Ryzen 1000 to Ryzen 9000 and Ryzen AI 400, are affected. For server models, AMD lists only the smaller desktop counterparts, Epyc 4004 and Epyc 4005, while excluding the multi-core variants under the 7000 and 9000 series designations. Intel has stated that its affected processors include desktop, notebook, and embedded models up to and including the Core Ultra 200 series. For server models, Intel lists processor lines up to the third-generation Xeon Scalable family (Ice Lake) released in 2021. Both AMD and Intel have already distributed updated firmware versions to manufacturers of desktop PCs, notebooks, and motherboards. Over the coming weeks and months, these manufacturers will provide corresponding BIOS updates. In addition, software patches are being developed for components such as the Debian library libtpms and various Windows versions. The discovery of these vulnerabilities highlights the importance of secure firmware implementation in hardware components that form the foundation of system trust. While the immediate risk to individual users is low due to the requirement for local privileged access, the potential impact on enterprise environments underscores the need for timely patching and robust security practices. Both AMD and Intel have taken proactive steps to mitigate the risks by distributing updated firmware and collaborating with operating system developers to ensure comprehensive protection against exploitation.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter