Vulnerabilidades en AMD

458 resultados
Análisis Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2023-31322HIGHType confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted EPSS 0.1%CVE-2021-26350—A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in EPSS 0.1%CVE-2021-46795MEDIUMA TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memoryEPSS 0.1%CVE-2024-21981MEDIUMImproper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution priEPSS 0.1%CVE-2025-61969HIGHIncorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resultiEPSS 0.1%CVE-2024-21947HIGHImproper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially reEPSS 0.1%CVE-2023-31323HIGHType confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory InterconEPSS 0.1%CVE-2024-36315MEDIUMImproper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensEPSS 0.1%CVE-2024-21970MEDIUMImproper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentiEPSS 0.1%CVE-2023-31305LOWGeneration of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to rEPSS 0.1%CVE-2023-31341HIGHInsufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-ofEPSS 0.1%CVE-2024-36346MEDIUMImproper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input daEPSS 0.1%CVE-2024-36319MEDIUMDebug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causinEPSS 0.1%CVE-2024-21971MEDIUMImproper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, rEPSS 0.1%CVE-2026-0466MEDIUMImproper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentialEPSS 0.1%CVE-2025-52538HIGHImproper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resultingEPSS 0.1%CVE-2024-36326HIGHMissing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, poteEPSS 0.1%CVE-2024-36352HIGHImproper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to aEPSS 0.1%CVE-2025-48515MEDIUMInsufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwEPSS 0.1%CVE-2025-61972HIGHMissing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMEPSS 0.1%