ZeroHour

CVE-2021-26311

CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description

In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

Vendors
amd
Products
epyc 7232p, epyc 7251, epyc 7252, epyc 7261, epyc 7262, epyc 7272, epyc 7281, epyc 7282, epyc 72f3, epyc 7301, epyc 7302, epyc 7302p
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news