ZeroHour

CVE-2021-26398

CVSS 3.1
7.8 high
EPSS
<1%p11
Published
()
Modified
Description

Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.

Vendors
amd
Products
epyc 7h12 firmware, epyc 7f72 firmware, epyc 7f52 firmware, epyc 7f32 firmware, epyc 7742 firmware, epyc 7702p firmware, epyc 7702 firmware, epyc 7662 firmware, epyc 7642 firmware, epyc 7552 firmware, epyc 7542 firmware, epyc 7532 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.