Intel

AMD Ryzen CPUs are impacted by all of these serious vulnerabilities

Serving the tech enthusiast community for over 25 years.
TechSpot means tech analysis and advice you can trust . Read our ethics statement .

A hot potato: All users with AMD Ryzen processors from the last few years should check and update their motherboard firmware ASAP, especially if they haven't done so since before 2023. AMD has published a detailed chart describing four severe security issues affecting server, desktop, workstation, HEDT, mobile, and embedded Zen CPUs. Recent BIOS updates have addressed most, but not all of the flaws.

All four vulnerabilities AMD has acknowledged are marked as high-severity. The chart below lists the minimum AGESA version needed to mitigate all issues for each processor generation. A more detailed breakdown of which problems and solutions affect each CPU can be found in the company's security bulletin .

One of the vulnerabilities, designated CVE-2023-20576, can allow attackers to initiate denial of service attacks or escalate privileges due to insufficient data authenticity verification in the BIOS.

Two others – CVE-2023-20577 and CVE-2023-20587 – can enable arbitrary code execution by granting access to the SPI flash through System Management Mode. Another, dubbed CVE-2023-20579, can cause loss of integrity and availability through improper access control in AMD's SPI protection feature.

CPU GenerationMinimum Patched BIOS versionAvailability Date
1st Gen AMD EPYCNaplesPI 1.0.0.K2023-Apr-27
2nd Gen AMD EPYCRomePI 1.0.0.H2023-Nov-07
3rd Gen AMD EPYCMilanPI 1.0.0.C2023-Dec-18
4th Gen AMD EPYCGenoaPI 1.0.0.82023-Jun-09
Ryzen 3000 DesktopComboAM4 1.0.0.B 2024-Mar
Ryzen 5000 DesktopComboAM4v2 1.2.0.B2023-Aug-25
Ryzen 5000 Desktop w/ RadeonComboAM4v2PI 1.2.0.C2024-Feb-07
Ryzen 7000 DesktopComboAM5 1.0.8.02023-Aug-29
Ryzen 3000 Desktop w/ RadeonComboAM4 1.0.0.B 2024-Mar
Ryzen 4000 Desktop w/ RadeonComboAM4v2PI 1.2.0.C2024-Feb-07
Ryzen Threadripper 3000CastlePeakPI-SP3r3 1.0.0.A2023-Nov-21
Ryzen Threadripper Pro 3000WXChagallWSPI-sWRX8 1.0.0.72024-Jan-11
Ryzen Threadripper Pro 5000WXChagallWSPI-sWRX8 1.0.0.72024-Jan-11
Athlon 3000 Mobile w/ RadeonPollockPI-FT5 1.0.0.62023-Oct-26
Ryzen 3000 Mobile w/ RadeonPicassoPI-FP5 1.0.1.02023-May-31
Ryzen 4000 Mobile w/ RadeonRenoirPI-FP6 1.0.0.D 2024-Feb
Ryzen 5000 Mobile w/ RadeonCezannePI-FP6 1.0.1.02024-Jan-25
Ryzen 7020 w/ RadeonMendocinoPI-FT6 1.0.0.62024-Jan-03
Ryzen 6000 w/ RadeonRembrandtPI-FP7 1.0.0.A2023-Dec-28
Ryzen 7035 w/ RadeonRembrandtPI-FP7 1.0.0.A2023-Dec-28
Ryzen 5000 w/ RadeonCezannePI-FP6 1.0.1.02024-Jan-25
Ryzen 3000 w/ RadeonCezannePI-FP6 1.0.1.02024-Jan-25
Ryzen 7040 w/ RadeonPhoenixPI-FP8-FP7 1.1.0.02023-Oct-06
Ryzen 7045 MobileDragonRangeFL1PI 1.0.0.3b2023-Aug-30
Eypc Embedded 3000Snowyowl PI 1.1.0.B2023-Dec-15
Epyc Embedded 7002EmbRomePI-SP3 1.0.0.B2023-Dec-15
Epyc Embedded 7003EmbMilanPI-SP3 1.0.0.82024-Jan-15
Epyc Embedded 9003EmbGenoaPI-SP5 1.0.0.32023-Sep-15
Ryzen Embedded R1000EmbeddedPI-FP5 1.2.0.A2023-Jul-31
Ryzen Embedded R2000EmbeddedPI-FP5 1.0.0.22023-Jul-31
Ryzen Embedded 5000EmbAM4PI 1.0.0.42023-Sep-22
Ryzen Embedded V1000EmbeddedPI-FP5 1.2.0.A2023-Jul-31
Ryzen Embedded V2000EmbeddedPI-FP6 1.0.0.9 2024-Apr
Ryzen Embedded V3000EmbeddedPI-FP7r2 1.0.0.9 2024-Apr

Those with Ryzen 3000 series desktop CPUs, 4000 series mobile APUs, embedded V2000 chips, or V3000 systems should exercise extra vigilance over the next few months, as the issues affecting those generations have not all been patched. An update planned for later this month will address the vulnerabilities for the 4000 series APUs, while a March 2024 BIOS update will fix the 3000 series CPUs. The affected embedded products will receive patches in April.

All other Zen processors received the relevant fixes in updates between mid-2023 and early this month. For 2nd-gen Epyc processors, the update that mitigated last year's Zenbleed attack also protects against the new vulnerabilities.

There are several ways to check and update your BIOS version. In most modern PCs, both are possible directly from the BIOS itself. After entering the BIOS by pressing the indicated button during the system's initial boot-up, the version number should appear on the main menu. Automatic update functions vary depending on the motherboard manufacturer.

To check your BIOS version without rebooting Windows, launch the System Information app by typing that into search or "msinfo" into the taskbar's search. The version and date should appear in the list on the right pane. The latest BIOS version can usually be found on the support section of the motherboard manufacturer's website. All major motherboard makers also offer automatic updates through optional management software.

Share this article:

Tech Jobs: Find the next step in your career

Related Stories

Featured on TechSpot