來源cnBeta (Full RSS)•較早收集於 14h
AMD 被指拖延修補漏洞並拒付漏洞獎金

💡了解與硬體供應商漏洞獎勵計畫合作的風險,以保障您的研究成果。
⚡ 30 秒速覽
有什麼變化
AMD 被指控花費 124 天才處理回報的安全漏洞。
為什麼重要
此爭議可能損害 AMD 在白帽駭客社群中的聲譽,進而影響未來的負責任漏洞披露。這凸顯了硬體供應商建立清晰且不可變更的安全披露政策之重要性。
下一步行動
若您是安全研究員,在向硬體供應商提交重大漏洞前,請務必以書面形式記錄漏洞獎勵計畫的條款。
誰應關注:Researchers & Academics
關鍵要點
- •AMD 被指控花費 124 天才處理回報的安全漏洞。
- •據稱該公司追溯修改了漏洞獎勵計畫的條款。
- •研究員在政策變更後被拒付 1 萬美元獎金。
- •此事件引發網路安全社群對企業透明度的批評。
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 8 個來源。
🔑 增強重點摘要
- •The security researcher involved in the dispute is identified as Paul, also known as MrBruh.
- •The vulnerability (CVE-2026-40677) was a Remote Code Execution (RCE) flaw in AMD's auto-updater software, exploitable via a Man-in-the-Middle (MITM) attack due to insecure HTTP downloads and lack of proper certificate/signature validation.
- •AMD initially dismissed the reported bug as "out of scope" for its bug bounty program, despite it later receiving a CVSS 4.0 score of 7.7, indicating a significant severity.
- •AMD reportedly updated its bug bounty policy after the researcher's public disclosure gained traction, retroactively adding a clause that prohibits researchers from disclosing vulnerability information without AMD's written consent, even for out-of-scope reports.
- •The incident has drawn widespread criticism from the cybersecurity community, with experts warning that such corporate actions could undermine the integrity of coordinated vulnerability disclosure and deter future responsible reporting.
🛠️ 技術深入
- The vulnerability (CVE-2026-40677) was a Remote Code Execution (RCE) flaw found in AMD's auto-updater software.
- The core issue was that while the updater pulled its update list over HTTPS, the actual executable download links used plain HTTP.
- The updater reportedly lacked proper certificate validation or real signature checks before executing downloaded files, making it susceptible to Man-in-the-Middle (MITM) attacks.
- An attacker could exploit this by replacing legitimate update files with malicious executables, which would then run with elevated privileges due to the updater's permissions.
- Affected mitigated versions include AMD Ryzen Master 2.14.3, AMD µProf 5.3, and AMD Management Console 14.0.0.
- Although AMD reportedly reengineered the download code, the new version still uses the CRC32 hash for file validity checks, which is not considered cryptographically secure.
🔮 前景展望基於引用來源的 AI 分析
AMD's reputation among security researchers may suffer, potentially leading to fewer responsible disclosures.
The perceived retroactive policy change and denial of bounty could discourage researchers from reporting vulnerabilities to AMD, opting instead for public disclosure or selling flaws on the black market.
The incident could prompt other companies to review and clarify their bug bounty program terms to prevent similar disputes.
The controversy highlights ambiguities in bug bounty policies, particularly regarding out-of-scope findings and disclosure requirements, which other companies might seek to address proactively.
Increased scrutiny on corporate ethics in vulnerability disclosure and bug bounty programs is likely.
The debate sparked by this incident could lead to broader industry discussions and calls for more transparent and consistent practices in handling security research and rewards.
⏳ 時間線
2026-01-27
Security researcher MrBruh discovers an RCE vulnerability in AMD's auto-updater software.
2026-02-06
MrBruh reports the vulnerability to AMD through its bug bounty program.
2026-02
AMD initially closes the report as 'out of scope' and later requests MrBruh to temporarily remove his public blog post.
2026-06-09
AMD releases a fix for the vulnerability, 124 days after the initial finding.
2026-06-12
News breaks about AMD denying the $10,000 bug bounty and retroactively changing its bug bounty policy after MrBruh's public disclosure.
📎 來源 (8)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: cnBeta (Full RSS) ↗
每週電子報
每週一封,可隨時退訂。