CVE-2021-39298
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Affected
- hp/z1 entry tower g5 workstation firmware · hp/z1 entry tower g6 workstation firmware · hp/z1 g8 tower desktop pc firmware · hp/z4 g4 workstation \(core-x\) firmware · hp/z4 g4 workstation \(xeon w\) firmware · hp/z6 g4 workstation firmware · hp/z8 g4 workstation firmware · hp/engage flex mini retail system firmware · hp/mp9 g4 retail system firmware · hp/elite dragonfly firmware · hp/elite dragonfly g2 firmware · hp/elite dragonfly max firmware · hp/elite x2 1013 g3 firmware · hp/elite x2 g4 firmware · hp/elite x2 g8 tablet firmware · hp/elitebook 1050 g1 firmware · hp/elitebook 830 g5 firmware · hp/elitebook 830 g6 firmware · hp/elitebook 830 g7 firmware · hp/elitebook 830 g8 firmware · +40 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.