cbcvebase.
CVE-2021-46760
published 2023-05-09

CVE-2021-46760: A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may…

PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.78%
51.6th percentile
A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.

Affected

23 ranges
VendorProductVersion rangeFixed in
amd3rd_gen_amd_ryzen_threadripper_processors_castle_peak_hedt
amdryzen_3945wx_firmware
amdryzen_3945wx_firmware
amdryzen_3945wx_firmware
amdryzen_3955wx_firmware
amdryzen_3955wx_firmware
amdryzen_3955wx_firmware
amdryzen_3960x_firmware
amdryzen_3960x_firmware
amdryzen_3960x_firmware
amdryzen_3970x_firmware
amdryzen_3970x_firmware
amdryzen_3970x_firmware
amdryzen_3975wx_firmware
amdryzen_3975wx_firmware
amdryzen_3975wx_firmware
amdryzen_3990x_firmware
amdryzen_3990x_firmware
amdryzen_3990x_firmware
amdryzen_3995wx_firmware
amdryzen_3995wx_firmware
amdryzen_3995wx_firmware
amdryzen_threadripper_pro_processors_castle_peak_ws
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.