AMD disclosed the high-severity SinkClose processor vulnerability, tracked as CVE-2023-31315, affecting a broad range of AMD CPUs manufactured since 2006. The flaw can be exploited by an attacker who already has kernel-level access to manipulate System Management Mode (SMM) configuration, bypass SMM lock protections, and execute arbitrary code at the highly privileged Ring -2 level.
Researchers Enrique Nissim and Krzysztof Okupski of IOActive showed multiple exploitation paths, including abuse of the TSeg protection mechanism and access to sensitive data stored in SMRAM. AMD directed customers to obtain product-specific BIOS updates from their OEM or system vendor as the primary mitigation for affected platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
AMD warned about the high-severity SinkClose processor vulnerability, tracked as CVE-2023-31315, affecting many AMD CPUs produced since 2006. AMD advised customers to obtain product-specific BIOS updates from their OEM vendors to mitigate the issue.
IOActive researchers Enrique Nissim and Krzysztof Okupski demonstrated multiple ways to exploit the SinkClose flaw (CVE-2023-31315), including bypassing SMM protections, abusing TSeg, and accessing data in SMRAM. The vulnerability affects a broad range of AMD CPUs and requires prior kernel-level access to reach Ring -2 execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.