Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-46757HIGHInsufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel EPSS 0.2%CVE-2023-31352MEDIUMA bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private dEPSS 0.2%CVE-2021-26354MEDIUMInsufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory valEPSS 0.2%CVE-2025-0014HIGHIncorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentialEPSS 0.2%CVE-2021-46779HIGHInsufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASPEPSS 0.2%CVE-2024-36339HIGHA DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulEPSS 0.2%CVE-2021-26397HIGHInsufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resEPSS 0.2%CVE-2024-36349LOWA transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, poteEPSS 0.2%CVE-2024-21960HIGHIncorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilegeEPSS 0.2%CVE-2023-20587HIGHImproper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code EPSS 0.2%CVE-2023-20582MEDIUMImproper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults EPSS 0.2%CVE-2021-26355MEDIUMInsufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in EPSS 0.2%CVE-2021-46768MEDIUMInsufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentEPSS 0.2%CVE-2025-62625MEDIUMImproper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentiaEPSS 0.2%CVE-2025-62626HIGHImproper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruEPSS 0.2%CVE-2024-36342HIGHImproper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execuEPSS 0.2%CVE-2023-20581LOWImproper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss of guest memory intEPSS 0.2%CVE-2021-26383HIGHInsufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a comEPSS 0.2%CVE-2023-20601MEDIUMImproper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-EPSS 0.2%CVE-2021-26315When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficientEPSS 0.2%