← back
CVE-2023-20569

CVE-2023-20569

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 7.3%
exploitation probability
7.3%top 6% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in certain AMD processors allows attackers to manipulate how the CPU predicts where to return after function calls, causing it to speculatively execute code at attacker-chosen addresses and potentially leak sensitive information.

Technical detail

A side-channel vulnerability in AMD CPU branch prediction mechanisms enables an attacker to influence return address prediction without elevated privileges, inducing speculative execution at attacker-controlled addresses. This can lead to information disclosure through speculative execution side channels, particularly affecting processes running on the same physical core.

Summary generated and translated by AI from the official description.
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.