Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-26367MEDIUMA malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address ranEPSS 0.2%CVE-2024-36353MEDIUMInsufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over memory values potentialEPSS 0.2%CVE-2024-36328HIGHInteger overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or avaiEPSS 0.2%CVE-2025-48508MEDIUMImproper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control EPSS 0.2%CVE-2021-46746MEDIUMLack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with accessEPSS 0.2%CVE-2023-20507LOWAn integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data inEPSS 0.2%CVE-2023-31307LOWImproper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory readEPSS 0.2%CVE-2025-52541HIGHA DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary codEPSS 0.2%CVE-2023-20572MEDIUMAn observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message autheEPSS 0.2%CVE-2023-20540LOWAn observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message autheEPSS 0.2%CVE-2024-36331LOWImproper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulEPSS 0.2%CVE-2025-0032HIGHImproper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcoEPSS 0.2%CVE-2021-26410LOWImproper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memoEPSS 0.2%CVE-2021-26381HIGHImproper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping operations on a larEPSS 0.2%CVE-2025-29950HIGHImproper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary cEPSS 0.2%CVE-2023-31331LOWImproper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stacEPSS 0.2%CVE-2023-31304LOWImproper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to modify the PCIe® lanEPSS 0.2%CVE-2021-26377MEDIUMInsufficient parameter validation while allocating process space in the Trusted OS (TOS) may allow for a malicious userspace process to trigEPSS 0.1%CVE-2024-21977LOWIncomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potEPSS 0.1%CVE-2023-31366LOWImproper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of EPSS 0.1%