AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
1–10 of 99 posts
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#2This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage.
If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI setup already, correct?
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#3AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
With this flaw, someone can just stick a bootable USB stick in your computer to mirror the LUKS/bitlocker disk drive and get access to the keys in the TPM which protect that drive.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#4AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#5AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
I think Intel's ME is much more complex than AMD's PSP. Does anyone know if AMD's PSP has a full network stack and the ability to interact with network hardware independent of the main CPU's OS?
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#6AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
TPM's are supposed to be resistant to physical attacks. With this flaw, someone can just stick a bootable USB stick in your computer to mirror the LUKS/bitlocker disk drive and get access to the keys in the TPM which protect that drive.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#7Earlier quoted context omitted.
I think Intel's ME is much more complex than AMD's PSP. Does anyone know if AMD's PSP has a full network stack and the ability to interact with network hardware independent of the main CPU's OS?
I had read somewhere that AMD PSP does not have Internet access.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#8AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
I think Intel's ME is much more complex than AMD's PSP. Does anyone know if AMD's PSP has a full network stack and the ability to interact with network hardware independent of the main CPU's OS?
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#9AMD PSP is basically their equivalent to Intel's ME, so this is not surprising... but then it says This function is called from TPM2_CreatePrimary with user controlled data - a DER encoded [6] endorsement key (EK) certificate stored in the NV storage. If I understand correctly, this is related to SecureBoot and to do such operations with the keys and certificates, the user has to have physical access to the BIOS/UEFI…
https://developer.arm.com/products/processors/cortex-m/sc300...