35
CVE-2020-12967
—CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
- Vendors
- amd
- Products
- epyc 7232p, epyc 7251, epyc 7252, epyc 7261, epyc 7262, epyc 7272, epyc 7281, epyc 7282, epyc 72f3, epyc 7301, epyc 7302, epyc 7302p
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H