Potential vulnerability in MSR could lead to arbitrary code execution
CVE-2023-31315
What is CVE-2023-31315?
CVE-2023-31315 is a potential vulnerability in AMD's model specific register (MSR) that could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution. The vulnerability affects the majority of AMD processors and has been patched by AMD in the Ryzen 3000 Series desktop processors. It has not been exploited by ransomware groups. Additionally, there are warnings about multiple cloud service provider attacks related to the Black Hat USA conference, and a potential vulnerability in Office that could lead to sensitive data leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
1st Gen AMD EPYC⢠Processors various
2nd Gen AMD EPYC⢠Processors various
3rd Gen AMD EPYC⢠Processors various
News Articles
References
CVSS V3.1
Timeline
- đ°
First article discovered by iThome
Vulnerability published
Vulnerability Reserved