Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxg4-qp5q-79p3

Опубликовано: 28 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

EPSS

Процентиль: 1%
0.00008
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.4
ubuntu
8 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 7.5
redhat
11 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
nvd
8 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
debian
8 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader ...

CVSS3: 6.4
fstec
больше 1 года назад

Уязвимость загрузчика обновлений микропрограммного обеспечения процессоров AMD связана с неправильной проверкой криптографической подписи. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код и отключить защиту System Management Mode (SMM)

EPSS

Процентиль: 1%
0.00008
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-347