Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-26337Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting inEPSS 0.2%CVE-2021-26327Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.EPSS 0.2%CVE-2021-26340A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation EPSS 0.2%CVE-2020-12894Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.EPSS 0.2%CVE-2023-20583Software based Power Side Channel on AMD CPUs EPSS 0.2%CVE-2021-26390A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity oEPSS 0.2%CVE-2024-21946HIGHIncorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalatiEPSS 0.2%CVE-2021-26366An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of systEPSS 0.2%CVE-2024-21945HIGHIncorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege eEPSS 0.2%CVE-2021-26369A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bouEPSS 0.2%CVE-2023-20511MEDIUMRelease of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentEPSS 0.2%CVE-2021-26361A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory frEPSS 0.2%CVE-2021-26400AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operaEPSS 0.2%CVE-2020-12960AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of servEPSS 0.2%CVE-2020-12954A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPIEPSS 0.2%CVE-2021-46778Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” EPSS 0.2%CVE-2025-29943MEDIUMWrite what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentiallyEPSS 0.2%CVE-2024-21939HIGHIncorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieEPSS 0.2%CVE-2021-46766LOWImproper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leEPSS 0.2%CVE-2021-26370Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allEPSS 0.2%