PT-2022-7168 · Amd · Amd Ryzen

Enrique Nissim

+2

·

Published

2022-10-27

·

Updated

2024-11-20

·

CVE-2023-20596

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AMD Ryzen (affected versions not specified)
Description The issue is related to insufficient input validation in the System Management Mode (SMM) Supervisor firmware of AMD Ryzen processors. This could allow a remote attacker to elevate privileges and impact the integrity, availability, and confidentiality of protected information. The vulnerability may enable an attacker with a compromised SMI handler to gain Ring0 access, potentially leading to arbitrary code execution. The issue is being actively exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-08567
CVE-2023-20596

Affected Products

Amd Ryzen