Description
A malicious or compromised UApp or ABL can send
a malformed system call to the bootloader, which may result in an out-of-bounds
memory access that may potentially lead to an attacker leaking sensitive
information or achieving code execution.




Published: 2023-05-09
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-33416 A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.
History

Mon, 27 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Amd Ryzen 3945wx Ryzen 3945wx Firmware Ryzen 3955wx Ryzen 3955wx Firmware Ryzen 3960x Ryzen 3960x Firmware Ryzen 3970x Ryzen 3970x Firmware Ryzen 3975wx Ryzen 3975wx Firmware Ryzen 3990x Ryzen 3990x Firmware Ryzen 3995wx Ryzen 3995wx Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2025-01-27T17:29:32.464Z

Reserved: 2022-03-31T16:50:27.869Z

Link: CVE-2021-46760

cve-icon Vulnrichment

Updated: 2024-08-04T05:17:42.578Z

cve-icon NVD

Status : Modified

Published: 2023-05-09T20:15:12.283

Modified: 2025-01-27T18:15:29.347

Link: CVE-2021-46760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses