Skip to main content

Update your AMD Ryzen drivers now to avoid password leaks

AMD released a new chipset driver in August that patched “critical security flaws,” but it didn’t mention which vulnerabilities the patch worked for. In a report published last week, cybersecurity researchers disclosed a vulnerability in the driver that would allow attackers to steal sensitive information like passwords, and it impacts all Ryzen processors, as well as several previous AMD generations.

The vulnerability (CVE-2021-26333) exists in AMD’s Platform Security Processor (PSP) chipset driver. The PSP works with the operating system to store sensitive information in secured parts of memory, and it’s usually only accessible by administrators.

AMD Ryzen processor in a motherboard.
Image used with permission by copyright holder

Kyriakos Economou, co-founder of security research firm ZeroPeril, published a report last week that said non-privileged users could exploit the driver to access the sensitive information stored in memory, according to The Record. Originally, AMD listed the vulnerability as only affecting Ryzen 1000 processors. The report says that all desktop and mobile Ryzen processors are affected, and AMD has updated its security disclosure since.

Recommended Videos

The attack focuses in the motherboard chipset, so it doesn’t apply if you have an AMD graphics card without an AMD processor (though another security flaw is posing a risk to AMD cards at the moment).

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

According to the report, Economou was able to leak “several gigabytes” of data. The exploit also allows attackers to get around mitigations like kernel address space layout randomization (KASLR), which protect against attacks that exploit a known address for the kernel. With these exploits, attackers can steal sensitive information like passwords and gain deeper permissions in a network.

Although scary, AMD has already patched the vulnerability with a new PSP chipset driver, which rolled out last week through Microsoft’s September Patch Tuesday. Read on learn how to update your drivers to make sure you have the latest version.

How to protect yourself

The latest version of the AMD PSP driver is 5.17.0.0, which is part of AMD Chipset Driver 3.08.17.735. You can install the driver manually, but it’s available now through Windows Update. To patch, press Windows Key + S, type “update,” and select Check for Updates. That will bring you to the Windows Update page.

Windows Update restarted required.
screenshot / Digital Trends

Then select Check for Updates and install any that are available. After that’s done, make sure to restart your computer to apply the new patches. Alternatively, you can download AMD’s auto-detect tool to install the latest Ryzen chipset drivers to your system. If you go this route, make sure to know your motherboard’s chipset and be certain that AMD PSP Driver is checked during the chipset driver installation.

If you arrive at Windows Update and don’t see anything, you can check to see if you have the latest chipset driver installed. Press Windows Key + X and select Device Manager. Expand the Security Devices list, right-click on AMD PSP, and select Properties. In the window that opens, select the Driver tab to view your driver version.

The secure version is 5.17.0.0, so you’ll need to update if your driver version is different. Although the vulnerability is mainly focused on recent Ryzen processors, it actually affects many generations of AMD CPUs. Here’s the full list:

  • 2nd Gen AMD Ryzen Mobile Processor with Radeon Graphics
  • 2nd Gen AMD Ryzen Threadripper processor
  • 3rd Gen AMD Ryzen Threadripper Processors
  • 6th Generation AMD A series CPU with Radeon Graphics
  • 6th Generation AMD A-Series Mobile Processor
  • 6th Generation AMD FX APU with Radeon R7 Graphics
  • 7th Generation AMD A-Series APUs
  • 7th Generation AMD A-Series Mobile Processor
  • 7th Generation AMD E-Series Mobile Processor
  • AMD A4-Series APU with Radeon Graphics
  • AMD A6 APU with Radeon R5 Graphics
  • AMD A8 APU with Radeon R6 Graphics
  • AMD A10 APU with Radeon R6 Graphics
  • AMD 3000 Series Mobile Processors with Radeon Graphics
  • AMD Athlon 3000 Series Mobile Processors with Radeon Graphics
  • AMD Athlon Mobile Processors with Radeon Graphics
  • AMD Athlon X4 Processor
  • AMD Athlon 3000 Series Mobile Processors with Radeon Graphics
  • AMD Athlon X4 Processor
  • AMD E1-Series APU with Radeon Graphics
  • AMD Ryzen 1000 series Processor
  • AMD Ryzen 2000 series Desktop Processor
  • AMD Ryzen 2000 series Mobile Processor
  • AMD Ryzen 3000 Series Desktop Processor
  • AMD Ryzen 3000 series Mobile Processor with Radeon Graphics
  • AMD Ryzen 3000 series Mobile Processor
  • AMD Ryzen 4000 Series Desktop Processor with Radeon Graphics
  • AMD Ryzen 5000 Series Desktop Processor
  • AMD Ryzen 5000 Series Desktop Processor with Radeon Graphics
  • AMD Ryzen 5000 Series Mobile Processors with Radeon Graphics
  • AMD Ryzen Threadripper PRO Processor
  • AMD Ryzen Threadripper Processor
Jacob Roach
Lead Reporter, PC Hardware
Jacob Roach is the lead reporter for PC hardware at Digital Trends. In addition to covering the latest PC components, from…
This Windows Update exploit is downright terrifying
Windows Update running on a laptop.

Windows Update may occasionally backfire with faulty patches, but for the most part, it's meant to keep us safe from the latest threats. Microsoft regularly pushes new patches that address potential vulnerabilities. But what if there were a tool that could undo every Windows Update and leave your PC exposed to all the threats Microsoft thought it had already fixed? Bad news: Such a tool now exists, and it's called Windows Downdate.

Don't worry, though. You're safe from Windows Downdate -- at least for now. The tool was developed as a proof-of-concept by SafeBreach researcher Alon Leviev, and although its potential is nothing short of terrifying, it was made in good faith as an example of something called "white-hat hacking," where researchers try to find vulnerabilities before malicious threat actors can do it first.

Read more
AMD Zen 5: everything we know about Ryzen 9000 and Ryzen AI 300
A hand holding AMD's Ryzen 9 9950X.

AMD Zen 5 is the next-generation Ryzen CPU architecture for Team Red, and its gunning for a spot among the best processors. After a major showing in June, the first Ryzen 9000 and Ryzen AI 300 CPUs are already here. AMD promises significant performance advantages for the new architecture that will give it a big leap in gaming and productivity tasks, and the company also claims it will have major leads over Intel's top 14th-generation alternatives, allowing it to compete among the best gaming processors.

Now that we've had the chips in hand for a while, here's everything you need to know about Zen 5, Ryzen 9000, and Ryzen AI 300.
Zen 5 release date, availability, and price
AMD originally confirmed that the Ryzen 9000 desktop processors will launch on July 31, 2024, two weeks after the launch date of the Ryzen AI 300. The initial lineup includes the Ryzen 9 9950X, the Ryzen 9 9900X, the Ryzen 7 9700X, and the Ryzen 5 9600X. However, AMD delayed the CPUs at the last minute, with the Ryzen 5 and Ryzen 7 showing up on August 8, and the Ryzen 9s showing up on August 15.

Read more
AMD’s new Ryzen 9000 CPUs are only cheaper in spirit
The AMD Ryzen 5 9600X between two finger tips.

Following up on reviews for the Ryzen 5 9600X and Ryzen 7 9700X, a flurry of reports are coming out about AMD's pricing for its new Zen 5 CPUs. Across the lineup, which is sure to earn some spots among the best processors, AMD reduced prices compared to the previous generation. That's great. But it's not exactly an accurate picture of pricing right now.

First, the prices. You can see in the picture below the prices for the main four Zen 5 CPUs. Both Ryzen 9 models are $50 cheaper compared to their last-gen counterparts, the Ryzen 7 9700X is $40 cheaper, and the Ryzen 5 9600X is $20 cheaper. That's only true if you compare the list prices that AMD set. Ultimately, it's up to retailers to dictate the final price, which is something we saw in full effect with AMD's last-gen CPUs.

Read more