CVE Published: 08/08/2023 |
CVE Updated: 24/10/2024 |
CVE Year: 2023 Source: AMD |
Vendor: AMD |
Product: Ryzen™ 3000 Series Desktop Processors “Matisse” AM4 Status : PUBLISHED
CVE-2023-20555 Description
Insufficient input validation in
CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting
an arbitrary bit in an attacker-controlled pointer potentially leading to
arbitrary code execution in SMM.