216.73.216.6

CVE-2023-52711

· Published 28/05/2024 07:15 · Modified 28/05/2024 12:39

Labels: CVE-2023-52711 2024-05-28CVE-2023-52711CWE-284[email protected]

Essential information

Published
28/05/2024 07:15
Modified
28/05/2024 12:39
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM memory thus potentially leading code execution in SMM

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References