Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxg4-qp5q-79p3

Опубликовано: 28 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

EPSS

Процентиль: 1%
0.00097
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 7.5
redhat
больше 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
nvd
около 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
debian
около 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader ...

CVSS3: 6.4
fstec
больше 1 года назад

Уязвимость функции load_ucode_amd_bsp() в модуле arch/x86/kernel/cpu/microcode/amd.c ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 1%
0.00097
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-347