ZeroHour

CVE-2020-12967

CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

Vendors
amd
Products
epyc 7232p, epyc 7251, epyc 7252, epyc 7261, epyc 7262, epyc 7272, epyc 7281, epyc 7282, epyc 72f3, epyc 7301, epyc 7302, epyc 7302p
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news