AMD Power Management Firmware Improper Validation Vulnerability Allowing Privileged Attackers to Manipulate Workload Arguments
Vulnerability
A vulnerability has been identified in the Power Management Firmware (PMFW) of AMD products, including certain graphics and datacenter accelerator products, as well as select client processors. This vulnerability arises from improper validation, which may enable an attacker with privileges to send malformed workload arguments when transferring table data from the System Management Unit (SMU) to Dynamic Random Access Memory (DRAM). Such manipulation could potentially lead to a loss of confidentiality and/or availability.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive data or disruption of services, causing a denial-of-service condition on the affected system.
Remediation
Users are advised to contact their AMD Customer Engineering representative for guidance on updating to the latest versions that address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
