Hardware giants Intel and AMD have released their latest round of patch updates, addressing more than 80 security flaws across hardware architectures, system management firmware, wireless drivers, and software development utilities. The updates highlight a recurring challenge for modern enterprise security operations: hardware-adjacent software, management engine firmware, and developer toolchains represent a critical attack surface that spans from end-user desktop workstations to multi-tenant cloud data centers. Addressing these Intel vulnerabilities and AMD flaws requires coordination between endpoint management teams, cloud infrastructure architects, and system administrators.
Intel Addresses High-Severity Firmware and Driver Vulnerabilities
Intel led the security releases with 42 new advisories covering 72 distinct vulnerabilities across its product portfolio. Prominently featured among the high-severity issues are flaws in Intel PROSet/Wireless WiFi software, which can be leveraged by attackers for local code execution, privilege escalation, and denial-of-service (DoS) attacks. Because wireless driver packages interface directly with low-level kernel driver stacks, privilege escalation bugs in these components allow an unprivileged local user or malicious application to gain high-level administrative or SYSTEM execution privileges on compromised endpoints.
Beyond consumer and endpoint driver packages, Intel patched critical high-severity bugs across its enterprise platform architecture and server processors:
- Converged Security and Management Engine (CSME) and Server Platform Services (SPS): High-severity privilege escalation bugs were resolved in CSME and SPS. These out-of-band management sub-processors run independently of the host operating system. A compromise of CSME or SPS allows an attacker with low-level administrative access to establish persistent, stealthy control beneath the operating system layer, bypassing standard host-based endpoint detection and response (EDR) agents.
- Intel Xeon Processors and Trust Domain Extensions (TDX): High-severity privilege escalation vulnerabilities were fixed in Intel Xeon chips and TDX. TDX is designed to create hardware-isolated execution environments (Trust Domains) that shield virtual machine workloads from a potentially untrusted or compromised hypervisor. Vulnerabilities in this layer undermine confidential computing promises in public and private cloud environments.
- Active Management Technology (AMT) and DCAP: Intel resolved a high-severity DoS flaw in AMT, its remote out-of-band enterprise management suite, alongside information disclosure issues in Data Center Attestation Primitives (DCAP), which are used to verify the integrity of hardware enclaves.
- Alias Checking Trusted Module: A high-severity privilege escalation issue affecting the Alias Checking Trusted Module on Xeon processors was also resolved.
Intel also resolved dozens of medium-severity vulnerabilities in its expanding artificial intelligence and machine learning ecosystem, including the Intel Extension for PyTorch, Extension for TensorFlow, LLM-on-Ray, Gaudi Container Runtime, vLLM Hardware Plugin for Gaudi, Neural Compressor, and AI Reference Models. Hardware and firmware updates were also released for Intel Core Ultra processors, NPU drivers, UEFI Reference BIOS, and Slim Bootloader.
AMD Patches Vitis Developer Tools, Ryzen Master, and SEV-SNP
AMD issued five security advisories addressing a dozen vulnerabilities across its software utilities and hardware virtualization features. The primary focus of AMD’s release centers on the AMD Vitis development environment, which received patches for five high-severity vulnerabilities. Vitis is used extensively by embedded engineers and software developers to construct applications targeting AMD FPGAs, adaptive SoCs, and AI accelerators. Exploitation of these Vitis vulnerabilities could enable arbitrary code execution, local privilege escalation, and private cryptographic key disclosure. In enterprise dev environments, flaws in software construction tools present severe supply chain risks, allowing attackers to introduce backdoor logic or extract sensitive signing keys during the build process.
In addition to Vitis, AMD patched arbitrary code execution vulnerabilities across key system administration and virtualization tools:
- Ryzen Master Utility: A widely used application for Windows-based CPU overclocking and performance tuning, Ryzen Master requires low-level kernel drivers to function. Code execution vulnerabilities in Ryzen Master provide local attackers with an avenue for kernel-level privilege escalation.
- Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP): AMD resolved an arbitrary code execution issue in its confidential computing architecture. Much like Intel’s TDX, SEV-SNP encrypts and isolates guest virtual machines from the host hypervisor. Exploitative code execution in this layer weakens tenant isolation boundaries relied upon by cloud service providers.
- Power Design Manager: An arbitrary code execution vulnerability was patched in AMD’s system power modeling software.
These updates follow earlier security advisories from AMD concerning the Safe RET interrupt vulnerability and “PowerHooK,” a research-backed side-channel attack method targeting SEV-protected virtual machines.
Risk Assessment and Remediation
The blast radius for these vulnerabilities depends heavily on the component affected. Hardware management engine flaws (Intel CSME/SPS) and confidential computing vulnerabilities (Intel TDX, AMD SEV-SNP) pose direct risks to data center integrity and cloud virtualization boundaries. Meanwhile, driver vulnerabilities (PROSet/Wireless, Ryzen Master) and developer tools (AMD Vitis, Intel PyTorch extensions) expose endpoint devices and software build pipelines to local exploitation and supply chain tampering.
Organizations should execute the following mitigation actions:
- Server and Cloud Infrastructure: Apply updated motherboard BIOS and microcode updates provided by OEM server vendors (such as Dell, HPE, and Lenovo) to patch CSME, SPS, TDX, and SEV-SNP. Ensure out-of-band management interfaces like Intel AMT are strictly isolated on dedicated management networks.
- Client Workstations: Deploy updated Intel PROSet/Wireless WiFi driver packages and update AMD Ryzen Master installations across all managed Windows endpoints.
- Engineering and AI Workloads: Update instances of AMD Vitis and update Intel AI software frameworks—including TensorFlow/PyTorch extensions and Gaudi runtime packages—to their latest vendor-maintained versions.
Related content
Windows Plug and Play Auto-Install Abused for Local and Remote SYSTEM Elevation
Security NewsCritical RCE and SQLi Vulnerabilities Patched in WordPress Core
Security NewsCritical WordPress Pre-Auth RCE and SQLi Vulnerabilities Patched, Public PoC Available
ResearchWhy WPA3 SAE Kills the Offline Hashcat Attack Vector
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call