Lucene search

K
cveAMDCVE-2020-12890
HistoryDec 10, 2021 - 10:15 p.m.

CVE-2020-12890

2021-12-1022:15:07
AMD
web.nvd.nist.gov
23
cve-2020-12890
smm
amd
agesa
privilege escalation
arbitrary code execution
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

12.6%

Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.

Affected configurations

Nvd
Node
amdamd_generic_encapsulated_software_architectureMatch-
VendorProductVersionCPE
amdamd_generic_encapsulated_software_architecture-cpe:2.3:o:amd:amd_generic_encapsulated_software_architecture:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "AMD Processors",
    "vendor": "AMD",
    "versions": [
      {
        "status": "unaffected",
        "version": "Processor  EPYC"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2020-12890