Insufficient Input Validation in CpmDisplayFeatureSmm of AMD Products
CVE-2023-20555
Key Information:
Summary
A vulnerability exists in the CpmDisplayFeatureSmm component of AMD products, stemming from insufficient input validation. This flaw could allow attackers to manipulate SMM (System Management Mode) memory by overwriting an arbitrary bit in a pointer that they control. Exploiting this vulnerability could lead to unauthorized code execution within the protected SMM environment, potentially compromising the integrity and confidentiality of the system.
Affected Version(s)
Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics “Picasso” x86 various
Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Pollock” x86 various
Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Dali”/”Dali” FP5 x86 various
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved