Vulnerabilidades en AMD
443 resultadosCVE-2020-12904—Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure.EPSS 0.2%CVE-2024-21946HIGHIncorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalatiEPSS 0.2%CVE-2024-21945HIGHIncorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege eEPSS 0.2%CVE-2020-12899—Arbitrary Read in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or denial of service.EPSS 0.2%CVE-2021-26327—Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.EPSS 0.2%CVE-2021-26337—Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting inEPSS 0.2%CVE-2020-12894—Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.EPSS 0.2%CVE-2021-26390—A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity oEPSS 0.2%CVE-2024-21939HIGHIncorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieEPSS 0.2%CVE-2021-26366—An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of systEPSS 0.2%CVE-2021-26369—A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bouEPSS 0.2%CVE-2021-46766LOWImproper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leEPSS 0.2%CVE-2021-26361—A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory frEPSS 0.2%CVE-2021-26400—AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operaEPSS 0.2%CVE-2020-12960—AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of servEPSS 0.2%CVE-2022-27677HIGH
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low
privileges to modify files potentialEPSS 0.2%CVE-2020-12954—A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPIEPSS 0.2%CVE-2024-21938HIGHIncorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directEPSS 0.2%CVE-2024-21944MEDIUMImproper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a sysEPSS 0.2%CVE-2021-26332—Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.EPSS 0.2%