{"rewrite":{"id":"r_c09c2f23a551b4acf9f26f96","clusterId":"c_ed5502a0857c1a792a9e382a","slug":"amd-auto-updater-had-a-remote-code-execution-vulnerability","model":"deepseek-v4-flash","headline":"AMD Auto Updater Had a Remote Code Execution Vulnerability","summary":"Security researcher MrBruh found a remote code execution vulnerability in AMD's Auto Updater. The tool downloads executables over HTTP without signature verification, allowing man-in-the-middle attacks. AMD initially rejected the report from its bug bounty program but later assigned CVE-2026-40677 and recommended updates to affected products.","whyItMatters":"The case shows a gap between bug bounty program scope and actual security risk, with AMD's fix approach still drawing criticism from the researcher.","webCardHtml":"\u003cp\u003eMrBruh reported the flaw on February 6, 2026. Intigriti, which runs AMD\u0026#39;s bug bounty program, closed the report the same day as ineligible because the attack requires a man-in-the-middle position. After the researcher\u0026#39;s blog post gained traction on Hacker News, AMD\u0026#39;s PSIRT reopened the case. AMD assigned CVE-2026-40677 and recommended updates to AMD Management Console, Ryzen Master, and µProf. But MrBruh says Ryzen Master\u0026#39;s updated mechanism still uses only a CRC-32 check, not cryptographic signature verification, and calls AMD\u0026#39;s explanation inaccurate. The updater also cannot handle redirects from ati.com to drivers.amd.com, which may crash the update process.\u003c/p\u003e","blueskyPost":"AMD's bug bounty program rejected MrBruh's report before reversing course. The HTTP download pipeline lacked signature verification, a basic gap in a tool handling privileged updates.","twitterPost":"AMD rejected the vulnerability report before assigning a CVE. The tool downloads executables over HTTP without signature checks.","threadsPost":"AMD's bug bounty program initially rejected MrBruh's report of a remote code execution vulnerability in the AMD Auto Updater. The tool downloaded executables over HTTP without signature verification. AMD later assigned CVE-2026-40677 and issued fixes.","newsletterBlurb":"Security researcher MrBruh found a remote code execution vulnerability in AMD's Auto Updater. AMD's bug bounty program initially rejected the report, but after public attention the company assigned CVE-2026-40677 and recommended updates. The researcher criticizes the fix for still lacking cryptographic signature verification.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260615-amd-auto-updater-vulnerability-rce/\",\"title\":\"Remote Code Execution Vulnerability Found in AMD's Auto Updater: What Happened from Reporting to Disclosure\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4213,"outputTokens":570,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1781474037,"createdAt":"2026-06-14T21:45:14.000Z","publishedAt":"2026-06-14T21:49:57.000Z","updatedAt":"2026-06-14T21:49:57.000Z"},"cluster":{"id":"c_ed5502a0857c1a792a9e382a","canonicalTitle":"AMDの自動更新ツールに見つかったリモートコード実行の脆弱性、報告から公開までに何が起きたのか","representativeArticleId":"a_57131b50409e338aac116af6","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-14T21:00:00.000Z","lastSeenAt":"2026-06-14T21:00:00.000Z","updatedAt":"2026-06-14T21:49:57.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260615-amd-auto-updater-vulnerability-rce/","title":"AMDの自動更新ツールに見つかったリモートコード実行の脆弱性、報告から公開までに何が起きたのか"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["Security researcher MrBruh reported a remote code execution vulnerability in AMD's Auto Updater on February 6, 2026.","The tool downloads executables over HTTP without signature verification, enabling man-in-the-middle attacks.","AMD initially rejected the bug bounty report but later assigned CVE-2026-40677 after the researcher's blog post gained traction on Hacker News.","AMD recommended updates to AMD Management Console, Ryzen Master, and µProf, but MrBruh says Ryzen Master's fix still uses only a CRC-32 check, not cryptographic signature verification.","The updater cannot handle redirects from ati.com to drivers.amd.com, which may crash the update process."]}
