Heap Overflow Vulnerability in AMD SMM Module
CVE-2023-20577
7.4HIGH
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2023-20577?
A heap overflow vulnerability in the System Management Mode (SMM) module of AMD platforms could allow attackers to exploit a secondary vulnerability that enables unauthorized write access to SPI flash memory. This exploitation could potentially lead to arbitrary code execution, compromising the integrity and security of the affected systems.
Affected Version(s)
2nd Gen AMD EPYC™ Processors RomePI 1.0.0.H
3rd Gen AMD EPYC™ Processors MilanPI 1.0.0.C
4th Gen AMD EPYC™ Processors GenoaPI 1.0.0.8