PT-2022-7387 · Amd · Amd Processors

Hugo Magalhaes

+1

·

Published

2022-01-21

·

Updated

2024-08-29

·

CVE-2022-23829

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AMD processors (affected versions not specified)
Description A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections. This issue is related to insufficient protection of service data and may allow an attacker to bypass security restrictions, elevate privileges, or execute arbitrary code. The flaw potentially impacts millions of devices worldwide.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-05098
CVE-2022-23829

Affected Products

Amd Processors