Attackers Can Modify Communications Buffer for Arbitrary Code Execution
CVE-2023-20578
6.4MEDIUM
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2023-20578?
A vulnerability exists in the AMD BIOS stemming from a Time-of-Check Time-of-Use (TOCTOU) issue. This flaw can be exploited by attackers who have ring0 privileges and access to critical system components such as the BIOS menu or UEFI shell. By leveraging this vulnerability, an attacker could potentially alter the communications buffer, leading to the execution of arbitrary code. This capability raises significant security concerns as it may allow unauthorized access and control over affected systems.
Affected Version(s)
AMD EPYC™ 7001 Processors NaplesPI 1.0.0.K
AMD EPYC™ 7002 Processors RomePI 1.0.0.G
AMD EPYC™ 7003 Processors MilanPI 1.0.0.B