Potential Vulnerability in AMD PSP1 Configuration Block Could Allow Arbitrary Code Execution
CVE-2021-26344
8.2HIGH
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2021-26344?
An out of bounds memory write vulnerability occurs when processing the AMD PSP1 Configuration Block (APCB), which could enable an attacker with necessary access to alter the BIOS image. This flaw could potentially be exploited to modify the APCB block, allowing for arbitrary code execution. Attackers capable of signing the modified BIOS images could leverage this vulnerability, potentially leading to severe security implications.
Affected Version(s)
AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics various
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics various
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics various