| |
A security researcher discovered a Remote Code Execution vulnerability in AMD's AutoUpdate software that allows attackers on a network to execute malicious code by intercepting unencrypted HTTP downloads, since the software lacks certificate validation. AMD initially rejected the vulnerability report as out of scope under their bug bounty program's MITM exclusion, but reversed course after public attention on Hacker News, committing to issue a CVE and provide credit while requesting an extended embargo longer than the industry standard 90 days.
Read Full Article →
← More Tech news