VulnerabilityModified
CVE-2020-12967
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
HIGH 7.2EPSS 1.68%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.68% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- amd/epyc 7232p · amd/epyc 7251 · amd/epyc 7252 · amd/epyc 7261 · amd/epyc 7262 · amd/epyc 7272 · amd/epyc 7281 · amd/epyc 7282 · amd/epyc 72f3 · amd/epyc 7301 · amd/epyc 7302 · amd/epyc 7302p · amd/epyc 7313 · amd/epyc 7313p · amd/epyc 7343 · amd/epyc 7351 · amd/epyc 7351p · amd/epyc 7352 · amd/epyc 7371 · amd/epyc 73f3 · +40 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.