AMD EPYC 7003
cpe:2.3:h:amd:epyc_7002:*:*:*:*:*:*:*, +3 more
A vulnerability exists in the AMD Platform Configuration Blob (APCB) System Management Mode (SMM) driver due to incorrect use of the LocateProtocol service in the EFI_BOOT_Services table. This flaw could enable a privileged attacker with local access (Ring 0) to escalate privileges to SMM, potentially leading to arbitrary code execution.
Exploitation of this vulnerability could allow for unauthorized privilege escalation to System Management Mode, with the potential for arbitrary code execution.
Users are advised to update to the Platform Initialization (PI) versions specified for their AMD EPYC or Ryzen processors. Consult the AMD security bulletin AMD-SB-7054 for detailed update instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.