AMD patched a critical vulnerability in its auto-updater tool that could allow remote code execution through man-in-the-middle attacks. The fix arrived 124 days after the researcher first reported the flaw to the vendor. AMD declined a $10,000 bug bounty claim because its policy excludes rewards for vulnerabilities exploited via MITM techniques.
Security patch arrives after 124 days while vendor denies researcher bounty claim
The software update targets the standalone auto-updater utility that distributes driver packages across Windows systems. The patch reengineers how the tool downloads files by adding secure transfer methods. AMD kept CRC32 hash validation in place despite the known weakness in that checksum method. The company also expanded the scope beyond Ryzen Master to include other utilities in future releases.
A security researcher initially disclosed the issue and requested a standard 90-day embargo window before public reporting. AMD agreed to the timeline but later indicated it needed more time for additional tools affected by the same class of bugs. The researcher now regrets accepting that initial agreement after the patch released without further negotiation on disclosure terms.
Community observers noted the bug likely never triggered in real-world conditions because the vulnerable code path remained inactive during normal operation. This observation suggests the flaw existed in the architecture but did not manifest as an active exploit vector for most users. The updater still received a full security fix regardless of practical impact.
AMD confirmed it fixed the vulnerability and updated its driver distribution pipeline. The company maintains that MITM-related flaws fall outside its standard bounty program rules. The patch ships to affected systems through the regular auto-updater channel.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.