LB: this is *fucking nuts*.
on certain AMD CPUs you can just poke a random MMIO address from ring 0 and change the memory controller's scrambling pattern, on a live system, which completely jumbles the mapping between physical addresses and DRAM IC coordinates. since all memory protection features (IOMMU, SMM boundaries, etc.) are based on physical addresses, it bypasses *all of them*. you can read AND WRITE the SMM, fTPM, and even the C6 microcode save regions. wild.