Improper Access Control Vulnerability in AMD System Management Mode
CVE-2022-23821
9.8CRITICAL
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 14 November 2023
What is CVE-2022-23821?
This vulnerability involves improper access control within System Management Mode (SMM), which may permit an attacker to write to the Serial Peripheral Interface (SPI) ROM. Exploitation of this vulnerability could potentially lead to arbitrary code execution, posing significant security risks to affected systems. It is crucial for users and administrators of AMD platforms to be aware of this issue and implement necessary security measures to safeguard their environments.
Affected Version(s)
AMD Ryzen™ Embedded 5000 various
AMD Ryzen™ Embedded R1000 various
AMD Ryzen™ Embedded R2000 various