PT-2018-1085 · Amd · Ryzen Mobile+3
Published
2018-03-12
·
Updated
2020-08-24
·
CVE-2018-8930
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips (affected versions not specified)
Description
The issue is related to the insufficient enforcement of Hardware Validated Boot in AMD processor chips. This allows an attacker with administrative privileges and access to the targeted computer to bypass code verification during the secure boot process. The attacker can then inject malicious code into the computer's BIOS by modifying the flash memory content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amd Epyc Server
Ryzen
Ryzen Mobile
Ryzen Pro