Security Vulnerabilities processor with unpatched AMD AGESA PI in Acer Swift 3 SF314-43-R2LX

13»

Answers

  • Marty11
    Marty11 Member Posts: 119 Skilled Fixer WiFi Icon
    edited July 5

    Dear @billsey

    Your help is much appreciated. You do good things in the community.

    I bought the best spec'ed rig at the time. AMD processors were outperforming Intel big time on almost all planes at that moment.

    I was under the assumption that I would be out of the dog house when it comes to driver and security support. But heck was I wrong. When I bought it at the beginning of 2022 it had just been released (the previous Christmas). I could have never imagined that Acer would do little to nothing to propagate AMD's security patches to its users.

    Once a security leak is published then the devil is out of the box and all live machines are at risk and have to be patched as soon as possible. Acer dropped the ball big time and didn't propagate AMD's patches to its users. I am very disappointed at this. And now after two years of lagging, Acer's message is that your system is EOL, you're on your own.

    That just isn't good enough. I've had an unsecurable machine for two years now, which will never be secure.

    Regarding JackE, should I take people seriously that descibe CVE recommendations as geek speak. Who make plain wrong statements about introduction moments of new systems (that are still on sale). And who describe Acer support not reporting back to me for two years as there is no problem.

    Regarding the Intel platform, I had similar problems with Acer not propagating security patches (see here). Intel now seem to have found a way to circumvent OEM platform builders (according to you). That's not due to Acer's support though.

    All the problems seem to originate with vulnerable proprietary code in management engines (ME firmware on Intel, and AGESA PI on AMD) that do get patched promptly by the processor manufacturers but the patches are not propagated by Acer to its customers.

    I have bought an expensive new laptop which I can never get secure.