AMD EPYC 7002
cpe:2.3:h:amd:epyc_7002:*:*:*:*:*:*:*, +1 more
A vulnerability exists in the AMD CPU ROM microcode patch loader due to improper signature verification. This issue may enable an attacker with local administrator privileges to load malicious microcode patches. The potential consequences include a loss of integrity in x86 instruction execution, compromised confidentiality and integrity of data within the x86 CPU privileged context, and a breach of the System Management Mode (SMM) execution environment.
Exploitation of this vulnerability could lead to unauthorized execution of malicious microcode, disrupting x86 instruction integrity and compromising data confidentiality and integrity in privileged CPU contexts, along with the SMM execution environment.
Users are advised to update to the latest Platform Initialization (PI) firmware versions available for their specific AMD processor series. Instructions for obtaining these updates can be found on the AMD Product Security Bulletin page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.