Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.
The takeaway: AMD has published a new security bulletin about the Trusted Platform Module reference implementation used in its computer platforms. The disclosed flaws could have significant reliability and security implications, but updates for AMD's numerous CPU families have already been available for months. Users simply need to install them.
Researchers working with the Trusted Computing Group recently identified a potential security issue in AMD's TPM code, prompting the company to release new motherboard and firmware updates to address the vulnerability. The update process was not exactly swift, however, as the fixed TPM code had already been available for months. Meanwhile, AMD has only just released its AMD-SB-7064 bulletin detailing the issue.
The US chipmaker explained that the TCG Vulnerability Response Team was informed by Intel researchers about a potential out-of-bounds read vulnerability in its TPM 2.0 reference code. The flaw could be exploited by local attackers with elevated user privileges, allowing them to force the TPM code to read sensitive data stored in the firmware or even affect the availability of the TPM.
AMD programmers confirmed the issue, which affects the company's TPM implementation in two different ways. The first flaw (CVE-2026-6726) could leak information and allow a malicious actor to recover credentials from a TPM-aware Certificate Authority, potentially enabling them to falsify TPM encryption keys or other TPM-based attestation mechanisms.

AMD describes the second flaw (CVE-2026-6727) as a timing side-channel vulnerability affecting decryption workloads using the RSA cryptosystem. The flaw could allow an attacker to decrypt encrypted data or falsify TPM 2.0 attestation keys. Both vulnerabilities require a local attack with "privileged" user access, meaning they should not pose a significant security risk to systems exposed solely to the internet.
Threat level aside, the two flaws have been assigned relatively high CVSS scores of 8.5 and 8.3, respectively, and are noteworthy for the large number of affected processors. AMD's list includes Epyc 4004 and 4005 Series CPUs, several embedded processors, Ryzen desktop CPUs from the 3000 through 9000 series, Threadripper workstation processors, and more.
AMD recommends that users install the updated Platform Initialization firmware releases designed to address both CVE-2026-6726 and CVE-2026-6727. The fixed firmware versions have been available since at least May for most processors, while Ryzen Embedded CPUs received their updated firmware in July.
The Trusted Platform Module is a security-focused cryptoprocessor specification defined by the TCG in 2003, but the major TPM 2.0 implementation upgrade has been available since 2014. A TPM 2.0 hardware module or firmware implementation became part of Windows 11's mandatory system requirements, providing a significant security improvement for the Windows ecosystem.
As these two AMD flaws clearly demonstrate, however, total security remains a distant goal even in the modern TPM-enabled PC world.








English (US) ·