Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2023-20565Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local EPSS 0.2%CVE-2023-20519A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's EPSS 0.2%CVE-2023-20563HIGHInsufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local EPSS 0.2%CVE-2021-26384A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentEPSS 0.2%CVE-2024-21925HIGHImproper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code exEPSS 0.2%CVE-2024-0179HIGHSMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentiaEPSS 0.2%CVE-2022-23829HIGHA potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native SystEPSS 0.2%CVE-2025-54520HIGHImproper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platfoEPSS 0.2%CVE-2021-26347Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in tEPSS 0.2%CVE-2025-54505LOWA transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor uEPSS 0.2%CVE-2021-26371MEDIUMA compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userEPSS 0.2%CVE-2021-26409HIGHInsufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SEPSS 0.2%CVE-2021-26382An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of EPSS 0.2%CVE-2024-21972MEDIUM An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformedEPSS 0.2%CVE-2024-21979MEDIUM An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformedEPSS 0.2%CVE-2023-20584MEDIUMIOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privilegeEPSS 0.2%CVE-2024-36343MEDIUMImproper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bEPSS 0.2%CVE-2021-26320Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacEPSS 0.2%CVE-2023-20594Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.EPSS 0.2%CVE-2021-26407MEDIUMA randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information discloEPSS 0.2%