AMD has released fixes for two high-severity TPM vulnerabilities affecting several Ryzen processors used in Windows 11 devices. The AMD TPM flaws could allow an attacker with elevated privileges to access sensitive TPM data or disrupt protections such as BitLocker and Windows Hello.

TPM protects keys and Windows 11 security features

The Trusted Platform Module, or TPM, is a hardware security component that handles cryptographic tasks separately from a computer’s main processor.

TPM 2.0 can store encryption keys, passwords, certificates and other sensitive data. It also helps generate random values, encrypt and decrypt information, and verify digital signatures.

Windows 11 relies on TPM 2.0 for several security functions. These include Windows Hello, which supports secure sign-in options, and BitLocker, which protects data through disk encryption.

Because TPM 2.0 is a Windows 11 system requirement, the AMD TPM flaws could affect a large number of Ryzen-powered devices.

Two vulnerabilities affect AMD Ryzen processors

AMD identified the two vulnerabilities as CVE-2026-6726 and CVE-2026-6727.

The flaws received CVSS severity scores of 8.5 and 8.3, placing both issues in the high-severity category.

According to AMD, an attacker would need elevated privileges on an affected system before attempting exploitation. Once they have that level of access, they could send malicious commands to the TPM 2.0 component in certain Ryzen processors.

A successful attack could allow the attacker to read information stored in the TPM, including private cryptographic keys.

Attackers could disrupt BitLocker and Windows Hello

Beyond data exposure, the vulnerabilities could allow an attacker to disable the TPM’s security functions.

Disabling the TPM could interfere with Windows features that rely on the chip. That may prevent BitLocker from functioning correctly or affect Windows Hello authentication protections.

The requirement for elevated privileges limits the risk of a remote, unauthenticated attack. However, attackers who already gained administrator-level access could use the flaws to weaken local security controls and access sensitive cryptographic material.

This makes prompt patching important, particularly for business devices that handle confidential information or use BitLocker encryption.

AMD recommends BIOS firmware updates

AMD has worked with motherboard manufacturers to address the vulnerabilities through updated Platform Initialization firmware.

Users should check their motherboard or system manufacturer’s support page for the latest BIOS update. Installing the update should include the Platform Initialization firmware fixes needed to address the affected TPM behaviour.

Before applying a BIOS update, users should follow the manufacturer’s instructions carefully and ensure the device has stable power. Organisations should also test firmware updates through their normal IT management process before broad deployment.

Keeping operating systems, firmware and security tools updated remains essential for protecting TPM-backed features and the sensitive data they store.


0 responses to “AMD patches TPM flaws that could expose keys and weaken Windows security”