CVE-2023-20577
massHeap Buffer Overflow in AMD SMM Firmware Module May Allow Arbitrary Code Execution
CVE-2023-20577 is a buffer overflow in the System Management Mode (SMM) module of AMD platform firmware (described as a heap overflow and tagged CWE-121), assigned by AMD's PSIRT and rated 7.4 (High) with a local attack vector and high attack complexity. It cannot be exploited on its own: an attacker needs local access and must already possess a second vulnerability that enables writing to SPI flash, after which the SMM overflow can be triggered. Successful exploitation potentially results in arbitrary code execution, with high impact on confidentiality, integrity, and availability in the system's firmware context. Any system running AMD platform firmware containing the affected SMM module is potentially affected, though this data does not specify concrete product names or version ranges, so defenders should consult AMD's security bulletin for their platforms. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days (5th percentile), so no exploitation has been observed.
What to do: Check AMD's security bulletin for the list of affected platforms and apply updated UEFI/BIOS or AGESA firmware from AMD and your board/system vendor when available; this data does not include specific fixed version numbers. Because exploitation requires chaining with a second vulnerability that permits SPI flash writes, also patch any known SPI flash write flaws and verify that SPI flash write protection is enabled on AMD systems. Prioritize remediation on systems where local attackers or malware execution are realistic threats.
| AMD SMM module (System Management Mode code in AMD platform/processor firmware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.