Vulnerabilidades en AMD

458 resultados
Análisis Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2023-20509MEDIUMAn insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, EPSS 0.1%CVE-2023-31325HIGHImproper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reservedEPSS 0.1%CVE-2025-0046HIGHIncorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.EPSS 0.1%CVE-2021-26368—Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unEPSS 0.1%CVE-2025-29951HIGHA buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privileEPSS 0.1%CVE-2025-48514MEDIUMInsufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potEPSS 0.1%CVE-2025-29939MEDIUMImproper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) duEPSS 0.1%CVE-2025-48517MEDIUMInsufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guesEPSS 0.1%CVE-2025-52536MEDIUMImproper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting iEPSS 0.1%CVE-2025-0012MEDIUMImproper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged EPSS 0.1%CVE-2023-31310MEDIUMImproper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set tEPSS 0.1%CVE-2023-31326LOWUse of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driveEPSS 0.1%CVE-2026-28237MEDIUMUnrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of avaEPSS 0.1%CVE-2024-36320HIGHInteger Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentialEPSS 0.1%CVE-2026-0438MEDIUMA System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker couEPSS 0.1%CVE-2025-48518MEDIUMImproper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integEPSS 0.1%CVE-2025-29949MEDIUMInsufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to wEPSS 0.1%CVE-2023-20508MEDIUMImproper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled bEPSS 0.1%CVE-2025-61970HIGHWeak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary codEPSS 0.1%CVE-2025-48503HIGHA DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting inEPSS 0.1%