Out of Bounds Write Vulnerability in APCB Firmware Could Lead to Arbitrary Code Execution
CVE-2022-23815
8.2HIGH
Key Information:
Summary
A security vulnerability exists in the AMD APCB firmware due to improper bounds checking. This flaw allows an attacker to execute out of bounds write operations, which may corrupt the APCB entry. Such corruption can lead to various security implications, including the potential for arbitrary code execution, posing significant risks to the integrity of affected systems.
Affected Version(s)
AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics various
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics PicassoPI-FP5 1.0.0.F
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics PollockPI-FT5 1.0.0.5
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database