PT-2022-7387 · Amd · Amd Processors
Hugo Magalhaes
+1
·
Published
2022-01-21
·
Updated
2024-08-29
·
CVE-2022-23829
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AMD processors (affected versions not specified)
Description
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections. This issue is related to insufficient protection of service data and may allow an attacker to bypass security restrictions, elevate privileges, or execute arbitrary code. The flaw potentially impacts millions of devices worldwide.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amd Processors