CVE-2023-31315
CVE-2023-31315
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Productos afectados
AMD · 1st Gen AMD EPYC™ ProcessorsAMD · 2nd Gen AMD EPYC™ ProcessorsAMD · 3rd Gen AMD EPYC™ ProcessorsAMD · 4th Gen AMD EPYC™ ProcessorsAMD · AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD EPYC™ Embedded 3000AMD · AMD EPYC™ Embedded 7002AMD · AMD EPYC™ Embedded 7003AMD · AMD EPYC™ Embedded 9003AMD · AMD Ryzen™ 3000 Series Desktop ProcessorsAMD · AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ GraphicsAMD · AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 5000 Series Desktop ProcessorsAMD · AMD Ryzen™ 5000 Series Desktop processor with Radeon™ GraphicsAMD · AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 6000 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7000 Series Desktop ProcessorsAMD · AMD Ryzen™ 7020 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7035 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7045 Series Mobile ProcessorsAMD · AMD Ryzen™ 8000 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ Embedded 5000AMD · AMD Ryzen™ Embedded 7000AMD · AMD Ryzen™ Embedded R1000AMD · AMD Ryzen™ Embedded R2000AMD · AMD Ryzen™ Embedded V1000AMD · AMD Ryzen™ Embedded V2000AMD · AMD Ryzen™ Embedded V3000AMD · AMD Ryzen™ Threadripper™ 3000 Series ProcessorsAMD · AMD Ryzen™ Threadripper™ PRO 3000WX Series ProcessorsAMD · AMD Ryzen™ Threadripper™ PRO Processors¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Enrique%20Nissim%20Krzysztof%20Okupski%20-%20AMD%20Sinkclose%20Universal%20Ring-2%20Privilege%20Escalation.pdfhttps://news.ycombinator.com/item?id=41475975https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.htmlhttps://www.darkreading.com/remote-workforce/amd-issues-updates-for-silicon-level-sinkclose-flaw