A Serious Security Flaw Affects Older AMD Processors

A newly disclosed security vulnerability has exposed a critical weakness in AMD processors manufactured between 2011 and 2015. Researcher Christopher Domas, known for uncovering significant CPU vulnerabilities, has identified an exploit that grants unauthorized access to restricted memory areas on affected chips. This discovery raises important questions for anyone still using older AMD hardware, particularly those in the FX-series desktop lineup and certain server processors.

The vulnerability, called Skitter Creek Bath Salts, leverages a single CPU instruction to disable memory mapping protections. Once activated, attackers can access normally inaccessible system areas including the Platform Security Processor, System Management Mode microcode, and other critical hardware-level controls. This represents a fundamental breach of the security architecture that protects modern computing systems.

Which Processors Are Actually Vulnerable

server data center technology
Photo by imgix

The exploit specifically targets AMD’s 15h and 16h processor families. The 15h family encompasses FX-series desktop CPUs and certain Opteron server chips released around 2011 to 2015. The 16h family includes lower-power processors based on the Jaguar and Puma architectures, such as those found in PlayStation 4 and Xbox One gaming consoles, along with select Athlon, Sempron, and Opteron-X models.

If you own a high-end gaming or workstation PC from the early-to-mid 2010s powered by an AMD processor, there is a reasonable chance your hardware falls into this vulnerable range. However, modern AMD processors manufactured after 2015 are not affected by this particular exploit, making this primarily a concern for legacy systems.

How the Exploit Works and What It Means

The technical mechanics behind this vulnerability involve a specific CPU setting called BankSwizzleMode, which controls how the processor organizes and accesses RAM. Modern processors deliberately jumble data across memory banks for performance reasons, creating a gap between what the operating system sees and where data actually sits in physical memory. This scrambling adds a layer of protection by hiding sensitive system areas from direct access.

The Skitter Creek exploit disables this scrambling with a single instruction, allowing an attacker with kernel-level access to map exactly where protected data resides. Once that mapping is known, the attacker can target specific locations containing classified code and data, essentially gaining complete control over the processor’s behavior. This is why security experts sometimes call such exploits the ultimate key to a system’s defenses.

For context, understanding these vulnerabilities matters for anyone managing older hardware or concerned about AMD CPU TPM security flaws. The ability to manipulate low-level processor operations would allow malicious code to bypass every software-based security measure, from encryption to firmware protections.

What You Should Do If You Own Affected Hardware

processor microchip circuit board
Photo by Chris Ried

AMD has confirmed that processors from the 15h and 16h families are no longer receiving security support updates. The company’s security bulletin emphasizes that exploiting this vulnerability requires kernel-level access, meaning an attacker must already have the ability to run custom drivers on your machine. In practical terms, this means the threat is limited to scenarios where someone with administrative privileges on your system becomes malicious, rather than a remote attack vector.

If you still rely on older AMD hardware for business or personal computing, consider whether your usage patterns expose you to this risk. Systems that run untrusted software, connect to untrusted networks, or serve multiple users face higher exposure. For those running isolated systems or single-user machines with careful software practices, the immediate danger may be lower.

The broader lesson here applies to anyone building or buying computers. Newer processor generations benefit from architectural improvements specifically designed to prevent exploits like this one. While you do not need to panic about older hardware you already own, this discovery reinforces why staying current with CPU technology matters for long-term security. When evaluating new systems, consider processors that offer updated security features, and stay informed about emerging CPU improvements and capabilities.

The Bigger Picture for CPU Security

This exploit represents one of many vulnerabilities discovered in processors over the past decade. Each discovery drives CPU manufacturers to implement better protections, faster isolation between privilege levels, and more robust verification of instruction execution. This ongoing security evolution is one reason why current-generation processors offer substantially better protection than models from ten years ago.

For consumers, the takeaway is straightforward: if you are shopping for a new CPU, choose modern options from current product lines. If you own older hardware, assess your actual security needs and update your software regularly. AMD’s acknowledgment that these chips are out of support means no patches will arrive, so your best defense remains good computing hygiene and awareness of what software you run.