Description: A researcher reported that a low-privileged attacker could create junction points to delete arbitrary files during the uninstallation of AMD μProf.
AMD has provided mitigation for this vulnerability.
AMD-SB-9013
CVE-2024-36340
2025-05-13
Spectre-v2 Domain Isolation, May 13, 2025
Description: Researchers from VU Amsterdam have shared with AMD a paper exploring the effectiveness of domain isolation against Spectre-v2 type attacks.
AMD believes the techniques described by the researchers are not applicable to AMD products.
AMD-SB-7034
2025-05-13
AMD Manageability Tools Vulnerabilities, May 13, 2025
Description: Researchers from ETH Zurich have provided AMD with a paper titled "Privilege Desynchronization: Cross-Privilege Spectre Attacks with Branch Privilege Injection."
AMD reviewed the paper and believes that this vulnerability does not impact AMD CPUs.
AMD-SB-7030
2025-02-11
AMD SMM Callout Vulnerability, Feb. 11 2025
Description: AMD SMM callout vulnerability in the AmdPlatformRasSspSmm driver supported on multiple processors.
Eclypsium reported an SMM callout vulnerability within the AmdPlatformRasSspSmm UEFI module, which is supported on various processors. The report noted that this vulnerability could allow attackers to execute arbitrary code within System Management Mode.
Analysis by AMD is that a ring 0 attacker could modify boot service tables to point to their own code, potentially resulting in arbitrary code execution. AMD has released mitigations to address this vulnerability.
AMD-SB-7028
CVE-2024-21924
2025-02-11
AMD SMM Vulnerabilities, Feb. 11 2025
Description: Quarkslab reported vulnerabilities that could allow attackers to execute code within SMM (System Management Mode).
CVE-2024-21925 is the result of a lack of sufficient input buffer(s) validation within the AmdPspP2CmboxV2 UEFI module. CVE-2024-0179 is an SMM (System Management Mode) Callout vulnerability within the AmdCpmDisplayFeatureSMM UEFI module. Both can allow ring-0 attackers to escalate their privileges, potentially resulting in arbitrary code execution. AMD has begun releasing firmware mitigations to fix these vulnerabilities.
Description: Potential vulnerabilities in AMD Embedded processors were reported, and mitigations are being provided through Platform Initialization (PI) firmware packages.
AMD-SB-5004
CVE-2023-20507
CVE-2023-20581
CVE-2023-31331
CVE-2023-20582
CVE-2023-20515
CVE-2023-31352
CVE-2023-31345
CVE-2023-31343
CVE-2023-31342
CVE-2023-31356
2025-02-11
AMD Server Processor Vulnerabilities , Feb. 11 2025
Description: Potential vulnerabilities in the AMD Secure Processor (ASP), AMD Secure Encrypted Virtualization (SEV), AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) and other platform components were discovered, and mitigations have been provided in AMD EPYC™ Platform Initialization (PI) firmware packages.
AMD-SB-3009
CVE-2023-20581
CVE-2023-20582
CVE-2023-31352
CVE-2023-31345
CVE-2023-31343
CVE-2023-31342
2024-12-09
Undermining Integrity Features of SEV-SNP with Memory Aliasing, Dec. 09, 2024
Description: Undermining Integrity Features of SEV-SNP with Memory Aliasing, Dec. 09, 2024
A team of researchers has reported to AMD that it may be possible to modify serial presence detect (SPD) metadata to make an attached memory module appear larger than it is, potentially allowing an attacker to overwrite physical memory.
AMD-SB-3015 –Undermining Integrity Features of SEV-SNP with Memory Aliasing
AMD-SB-3015
CVE-2024-21944
Affected Platforms and BIOS version numbers that contain the fix Details
2024-11-11
Return Address Stack Side Channel, Nov. 11, 2024
Description: Researchers from the Google® Security Team have reported to AMD a new method of exploiting the previously reported CVE-2023-20569 "Inception" vulnerability on "Zen 3" and "Zen 4" based architectures.
AMD believes that the mitigations outlined in AMD-SB-7005 "Return Address Predictor Security Notice" continue to protect against the exploit reported by the researchers.
AMD-SB-7031
Affected Platforms and BIOS version numbers that contain the fix Details