Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilitystandards-framework-update

AMD Draws Criticism After Denying Bounty for Auto-Updater MITM RCE Flaw

Updated 12d agoFirst seen Jun 12, 20262 sources

AMD fixed a critical remote code execution weakness in its auto-updater software after researcher Paul reported that downloads were being fetched over insecure HTTP, creating a man-in-the-middle path to deliver malicious code. The company took 124 days to ship a fix because multiple tools required coordinated updates, and the researcher later confirmed the software now retrieves drivers more securely. Reporting also noted lingering concerns about implementation details, including continued reliance on CRC32 for file validation, and claims from a Reddit user that the vulnerable updater path may not have been actively used, potentially requiring users to download a fresh version of AMD’s software to receive the remediation.

The dispute escalated after AMD allegedly refused to pay an expected $10,000 bug bounty, arguing that man-in-the-middle attacks were outside the scope of its program despite earlier indications that it would issue a CVE, credit the researcher, and address the flaw. Security community criticism intensified further after AMD was reported to have changed its disclosure and bounty rules to require non-disclosure even for findings deemed out of scope, a move critics said could discourage transparency and weaken incentives for independent vulnerability research.

Share:
AMD Draws Criticism After Denying Bounty for Auto-Updater MITM RCE Flaw
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 16, 202612d ago

AMD allegedly changes disclosure rules, prompting backlash

The dispute escalated when AMD was reported to have changed its bug bounty and disclosure rules to require non-disclosure even for out-of-scope bugs. Security community critics said the changes discourage transparency and undervalue researchers.

AMD faces backlash over alleged bug bounty denial and changed disclosure rules | brief | SC Media
Jun 12, 202616d ago

Researcher verifies fix but flags CRC32 validation weakness

After the update, Paul verified that the software now downloads drivers securely, but noted that it still uses CRC32 for file validation, which is not cryptographically secure.

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability - security flaw took 124 days to patch | Tom's Hardware

AMD ships coordinated fix after 124-day remediation period

AMD took 124 days to address the vulnerability, saying multiple affected tools required coordinated releases and reengineering of the download code. The updated software changed driver downloads to use a secure method.

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability - security flaw took 124 days to patch | Tom's Hardware

AMD denies bug bounty for reported updater vulnerability

AMD declined to pay the expected $10,000 bug bounty, saying its program policy did not cover man-in-the-middle attacks even though the reported issue could lead to remote code execution.

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability - security flaw took 124 days to patch | Tom's Hardware

AMD asks researcher to remove public blog post temporarily

After the disclosure, AMD asked the researcher to temporarily take down his public blog post about the vulnerability while the company worked on remediation.

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability - security flaw took 124 days to patch | Tom's Hardware

Researcher reports AMD auto-updater MITM RCE issue to AMD

A researcher identified as Paul reported a potential remote code execution vulnerability in AMD's auto-updater software caused by insecure HTTP downloads that enabled a man-in-the-middle attack path. AMD told him it would issue a CVE, fix the issue, and credit him, according to the report.

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability - security flaw took 124 days to patch | Tom's Hardware
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Organizations
5 linked
Advanced Micro DevicesTechRadarTom's HardwareMicrosoft CorporationReddit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.