Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-46771Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by EPSS 0.3%CVE-2023-20573LOWDebug Exception Delivery in Secure Nested PagingEPSS 0.3%CVE-2025-54518HIGHImproper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructionEPSS 0.3%CVE-2024-36348LOWA transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIEPSS 0.3%CVE-2021-46759MEDIUMImproper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a UapEPSS 0.3%CVE-2022-27672When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode EPSS 0.3%CVE-2020-12890Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or adminisEPSS 0.3%CVE-2025-52533HIGHImproper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromiEPSS 0.3%CVE-2020-12981An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the driver, potentially caEPSS 0.3%CVE-2020-12987A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.EPSS 0.3%CVE-2021-46767MEDIUMInsufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leadingEPSS 0.3%CVE-2024-21927MEDIUMImproper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters iEPSS 0.3%CVE-2021-26317Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary EPSS 0.3%CVE-2024-21958HIGHIncorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalationEPSS 0.3%CVE-2024-21957HIGHIncorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation pEPSS 0.3%CVE-2021-26339A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting iEPSS 0.3%CVE-2023-20561 EPSS 0.3%CVE-2021-26392Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with priEPSS 0.3%CVE-2023-20556 EPSS 0.3%CVE-2021-26386A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leaEPSS 0.3%