CVE-2021-39298

3 documents3 sources
Severity
8.8HIGH
EPSS
0.1%
top 82.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateFeb 17

Description

A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages192 packages

🔴Vulnerability Details

2
GHSA
GHSA-jxf5-m5fg-rw27: Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code2022-02-17
CVEList
CVE-2021-39298: A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting2022-02-16
CVE-2021-39298 (HIGH CVSS 8.8) | A potential vulnerability in AMD Sy | cvebase.io