Vulnerabilities in AMD CPU allow for code execution at the SMM level.

AMD has announced the resolution of six vulnerabilities in AMD EPYC and AMD Ryzen processors. The three most critical vulnerabilities (CVE-2023-31342, CVE-2023-31343, CVE-2023-31345) potentially allow for code execution at the System Management Mode (SMM) level, which has a higher priority than hypervisor mode and ring zero protection. Compromising SMM provides unrestricted access to all system memory and can be used for controlling the operating system. The vulnerabilities are caused by a lack of proper input validation in the SMM handler, allowing a privileged attacker to overwrite the contents of SMRAM. Details on the attack method have not yet been disclosed.

The other vulnerabilities:

  • CVE-2023-31352 — a flaw in the AMD SEV (Secure Encrypted Virtualization) firmware, used in virtualization systems for protection of virtual machines against interference from the hypervisor or host system administrator. Similar to the vulnerability fixed earlier in February, this issue allows an administrator with access to the host environment to read unencrypted memory contents, which may potentially contain sensitive data from the guest system.
  • CVE-2023-20582 — a way to bypass RMP (Reverse Map Table) checks when using the SEV-SNP (Secure Nested Paging) extension, designed for secure operation with nested page tables. An attacker with administrator rights can create conditions for a fault in the PTE (Page Table Entry) to circumvent protections for the integrity of virtual machine memory.
  • CVE-2023-20581 — an access control flaw in IOMMU, allowing a privileged attacker to bypass RMP checks and compromise the integrity of the guest system memory.

The vulnerabilities are present in the 3rd and 4th generation AMD EPYC server processors, in embedded CPUs from the AMD EPYC 7003 and 9004 series, in AMD Ryzen Embedded R1000, R2000, 5000, 7000, V2000, and V3000, in desktop series AMD Ryzen 3000, 4000, 5000, 7000, and 8000, as well as in the AMD Athlon 3000 series.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster