Attackers Can Modify Communications Buffer for Arbitrary Code Execution
CVE-2023-20578
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2023-20578?
A vulnerability exists in the AMD BIOS stemming from a Time-of-Check Time-of-Use (TOCTOU) issue. This flaw can be exploited by attackers who have ring0 privileges and access to critical system components such as the BIOS menu or UEFI shell. By leveraging this vulnerability, an attacker could potentially alter the communications buffer, leading to the execution of arbitrary code. This capability raises significant security concerns as it may allow unauthorized access and control over affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AMD EPYC™ 7001 Processors NaplesPI 1.0.0.K
AMD EPYC™ 7002 Processors RomePI 1.0.0.G
AMD EPYC™ 7003 Processors MilanPI 1.0.0.B
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved