A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM, potentially compromising the system’s confidentiality, integrity, and availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | AMD EPYC™ 4004 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 4005 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Ryzen™ 7000 Series Desktop Processors (Formerly Codenamed "Raphael") | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Ryzen™ 7000 Series Desktop Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Ryzen™ 7040 Series Mobile Processors With Radeon™ Graphics | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.