35
CVE-2021-26311
—CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description
In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
- Vendors
- amd
- Products
- epyc 7232p, epyc 7251, epyc 7252, epyc 7261, epyc 7262, epyc 7272, epyc 7281, epyc 7282, epyc 72f3, epyc 7301, epyc 7302, epyc 7302p
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H