Improper Input Validation in AmdPspP2CmboxV2 Driver by AMD
CVE-2024-21925

8.2HIGH

Key Information:

Summary

The AmdPspP2CmboxV2 driver from AMD contains an improper input validation issue that could allow a privileged attacker to manipulate system memory. By exploiting this vulnerability, an attacker may overwrite SMRAM, leading to potential arbitrary code execution and compromising system integrity. This flaw underscores the importance of rigorous input validation processes in driver development to ensure system security.

Affected Version(s)

AMD EPYC™ 7001 Processors Naples PI 1.0.0.N

AMD EPYC™ 7002 Processors Rome PI 1.0.0.K

AMD EPYC™ 7003 Processors Milan PI 1.0.0.E

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.