Source · Tier B · PreprintSource · Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack
Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack
M. Shen, Y. Qin. 2026. arXiv.
| Original | https://arxiv.org/abs/2605.12990 |
|---|---|
| DOI | 10.48550/arXiv.2605.12990 |
| arXiv | 2605.12990 |
| Version | Read the arXiv HTML on 2026-09-25; the abstract page could not be read by the fetch tool, so the version and submission date were not confirmed. No venue is given. |
| Accessed | 2026-09-25 |
| Note | Attack preprint (Institute of Software, Chinese Academy of Sciences). With root control of the host and the ability to rewrite the SPI flash, but no physical access, the attacker downgrades an EPYC Milan (Zen 3) platform to legacy AMD Secure Processor firmware, gains code execution there (MilanLaunchy) and extracts the full hardware root seed from which SEV-SNP's VCEK attestation keys are derived (BadFuse). The authors state this lets them forge attestation reports for any firmware version. Disclosed to AMD in January and April 2026; AMD's bulletin on MilanLaunchy is S-3131. |