A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU

Pipboy holds up an open padlock.
(Image credit: Bethesda)

Anyone owning an AMD CPU with Zen 1 - Zen 4 microarchitecture may want to double check their BIOS is up to date. According to Tom's Hardware, AMD CPUs with a BIOS patch earlier than 2014-12-17 have a vulnerability that allows anyone with local admin privileges to potentially upload new microcode to the units. This means altering the basic code which dictates how these CPUs run. This isn't something that's usually accessible or even visible outside of official AMD patches.

The exploit was discovered by a team of Google researchers who've been working alongside AMD, and it affects a tonne of chips released over the past eight years. This means if you're rocking something like the Ryzen 7 5700X3D from last year you could be vulnerable thanks to its Zen 3 architecture, whereas those with the AMD Ryzen 7 9800X3D should be safe with that newer Zen 5.

Now that the exploit is all fixed with the recent patch, the team have detailed their discovery and hacking processes made possible thanks to EntrySign, the microcode signature validation vulnerability in these chips. This includes how to hack it yourself, so if you're interested in jailbreaking your CPU maybe hold off on those updates.

EntrySign is exploitable thanks to a lack of proper encryption cryptographics. For these CPUs AMD was using the AES-CMAC function which is a message authentication code rather than a proper cryptographic hash function. With CMAC, anyone with the encryption key can see the steps in the encryption calculations, allowing them to reverse engineer and predict the outcome.

In this instance, AMD were using a publicly accessible NIST example key, making things all the more easier for potential bad actors. Hash functions that are properly designed for this kind of security don't have such keys to be exploited in the first case.

For security, this is pretty bad news. Having access to changing microcodes allows people to mess with the internal CPU buffers, and could have huge implications for security on virtual machines. The requirement of host ring 0 access is one of the saving graces in this exploit.

Host ring 0 refers to the most privileged layer of security as it talks directly to physical hardware. Basically we are talking about local admin privileges. The second ray of light is that any changes don't persist through a reboot, so power cycling any affected computers then immediately updating the BIOS should have you set.

The ability to remove changes on reboot also makes this a relatively safe project for anyone wanting to play with microcode on their CPU. It's not often we get such a close look at how processors actually run, so it's a good opportunity for the technology curious to get hands on.

The breakdown from Google gives you all the steps and tools you could need and Tavis Ormandy, one of Google's engineers on the project, proclaimed "jailbreak your AMD CPU" when sharing it on X, which isn't something you get the chance to do every day.

Best CPU for gamingBest gaming motherboardBest graphics cardBest SSD for gaming


Best CPU for gaming: Top chips from Intel and AMD.
Best gaming motherboard: The right boards.
Best graphics card: Your perfect pixel-pusher awaits.
Best SSD for gaming: Get into the game first.

TOPICS
Hope Corrigan
Hardware Writer

Hope’s been writing about games for about a decade, starting out way back when on the Australian Nintendo fan site Vooks.net. Since then, she’s talked far too much about games and tech for publications such as Techlife, Byteside, IGN, and GameSpot. Of course there’s also here at PC Gamer, where she gets to indulge her inner hardware nerd with news and reviews. You can usually find Hope fawning over some art, tech, or likely a wonderful combination of them both and where relevant she’ll share them with you here. When she’s not writing about the amazing creations of others, she’s working on what she hopes will one day be her own. You can find her fictional chill out ambient far future sci-fi radio show/album/listening experience podcast right here. No, she’s not kidding. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
ASRock X870 Steel Legend WiFi motherboard
Reddit reports of 9800X3D CPUs dying in ASRock motherboards are racking up fast, but a new BIOS update seemingly only addresses boot problems
Robert Hallock, VP of CCG at Intel, on stage at CES 2025.
Intel unveils second round of updates intended to bring Arrow Lake desktop chips up to expectations: 'our software for the 200S has reached full performance'
A screenshot from a YouTube video showing a sticker being pulled from the front of a fake 9800X3D CPU
This Amazon-bought fake AMD Ryzen 7 9800X3D is actually a 14-year-old Bulldozer chip with a cheap sticker on it
An artistic image where a digital progress bar is represented by a physical wooden block.
The nail-biting, 100-hour BIOS update stream which garnered 88,000 peak views ends with a cut to black
A close-up photo of AMD's AM4 CPU socket
Old AM4 CPUs including the Ryzen 5000 still make up 50% of AMD's sales today
AMD press slide detailing the Ryzen 9 9950X3D processor.
AMD's Ryzen 9 9950X3D and 9900X3D CPUs are rumoured to launch at the end of March at roughly the same time as the RX 9070-series GPUs
Latest in Processors
Nvidia CEO Jensen Huang delivering pancakes and sausages to pre-GTC show hosts and guests, wearing an apron
'There might be a party. I wasn't invited,' says Jensen Huang of the rumoured TSMC proposal to join forces and run Intel's chip fabs
Nvidia Feynman GPU
While we despair of RTX 50-series supplies and wait on next-gen Rubin, Nvidia reveals its next-next GPU architecture will be known as Feynman and is due in 2028
Nvidia Vera CPU
Nvidia reveals Vera, a new CPU with 'custom' cores which could be very exciting for its upcoming premium PC processor
Machinery tools and equipment,Rolls of galvanized steel for production metal pipes and tubes for industrial ventilation systems in factory.
New super-thin '2D' metal sheets could enable ultra-low power chips and can you guess how they're made? Yup, by squishing stuff really hard
Aooster's G-Flip 370 mini PC
This palm-sized PC has removable memory, a flip up screen, and a Ryzen AI 9 HX 370 processor
Texas Instruments MSPM0C1104 tiny chip
World's smallest microcontroller looks like I could easily accidentally inhale it but packs a genuine 32-bit Arm CPU
Latest in News
helldivers 2
'Never thought I'd go back' Helldivers 2 players steel themselves to return to the site of its most infamous battle, Malevelon Creek
Several adventurers in World of Warcraft Classic's hardcore server crying over the death of a fallen comrade.
Blizzard plans to revive WoW Classic Hardcore characters 'at our sole discretion', after DDOS attack puts major streamer guild OnlyFangs in the ground
Assassin's Creed Shadows change seasons - An upper-body shot of Yasuke looking cheerfully up into the distance.
Assassin's Creed Shadows is a hit and Steam played a 'significant role' in that: 27% of activations were on PC and it's the 2nd-biggest AC launch of all time
Typing on internet search toolbar: What am I doing?
How a Microsoft exec managed to pitch Microsoft Word through the genius tactic of being able to actually use it in a 'type-off' demanded by clients: 'I was the only one who'd actually been a secretary'
The outlast trials setting
'You just have to make them think this world is real, and this world can hurt you': The Outlast Trials devs discuss a changing horror genre and an insatiable need for scares
Half-Life wallpaper - Gordon Freeman
Former Valve exec says the company struggled to sell Half-Life until coming up with the ultimate 'one simple trick' of marketing manoeuvres: slapping a 'Game of the Year' sticker on the box