CVE-2023-20597
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Affected products
AMD · AMD EPYC™ Embedded 7003AMD · AMD Ryzen™ Embedded 5000AMD · AMD Ryzen™ Embedded V2000AMD · AMD Ryzen™ Embedded V3000AMD · Ryzen™ 3000 Series Desktop Processors “Matisse”AMD · Ryzen™ 5000 Series Desktop Processors “Vermeer”AMD · Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics “Cezanne”AMD · Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics "Barcelo"AMD · Ryzen™ 6000 Series Mobile Processors with Radeon™ Graphics "Rembrandt"AMD · Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics “Barcelo-R”AMD · Ryzen™ 7035 Series Mobile Processors with Radeon™ Graphics "Rembrandt-R"AMD · Ryzen™ Threadripper™ 3000 Series Processors “Castle Peak” HEDTAMD · Ryzen™ Threadripper™ PRO 3000WX Series Processors “Chagall” WS SP3AMD · Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3