On March 2018 CTS Labs published an advisory informing the public about the existence of 13 exploitable vulnerabilities in AMD processors. However, the technical details of these flaws has never been published.Since the last of AMDFlaws is now patched, our team is ready to reveal the technical details of our 8 months of research into the security of AMD’s latest Ryzen and Epyc processors.We have uncovered a total of 13 exploitable vulnerabilities, some inside AMD’s Platform Security Processor, and some inside the Ryzen chipset.We will cover the following topics:The approach we took to reverse engineer the undocumented Platform Security Processor, which runs on an isolated ARM processor located on the CPU die. We’ll explain how we built our own debugging infrastructure for the PSP (which is supposed to be impossible outside of AMD).How we bypassed digital signature verification to achieve code execution on the Platform Security Processor.How we leveraged backdoors in the chipset firmware to achieve code execution on the chipset’s internal 8051 processor.How we exploited flaws in the Platform Security Processor in real-time to inject code into SMM and VTL-1, which then allowed us to bypass Microsoft Credential Guard.Live demo!