Vulnerability Description
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 7 5700G Firmware | < comboam4v2_1.2.0.b |
| Amd | Ryzen 7 5700G | - |
| Amd | Ryzen 7 5700Ge Firmware | < comboam4v2_1.2.0.b |
| Amd | Ryzen 7 5700Ge | - |
| Amd | Ryzen 5 5600G Firmware | < comboam4v2_1.2.0.b |
| Amd | Ryzen 5 5600G | - |
| Amd | Ryzen 5 5600Ge Firmware | < comboam4v2_1.2.0.b |
| Amd | Ryzen 5 5600Ge | - |
| Amd | Ryzen 3 5300G Firmware | < comboam4v2_1.2.0.b |
| Amd | Ryzen 3 5300G | - |
| Amd | Ryzen 3 5300Ge Firmware | < comboam4v2_1.2.0.b |
| Amd | Ryzen 3 5300Ge | - |
| Amd | Ryzen 9 7950X3D Firmware | < comboam5pi_1.0.8.0 |
| Amd | Ryzen 9 7950X3D | - |
| Amd | Ryzen 9 7950X Firmware | < comboam5pi_1.0.8.0 |
| Amd | Ryzen 9 7950X | - |
| Amd | Ryzen 9 7900X3D Firmware | < comboam5pi_1.0.8.0 |
| Amd | Ryzen 9 7900X3D | - |
| Amd | Ryzen 9 7900 Firmware | < comboam5pi_1.0.8.0 |
| Amd | Ryzen 9 7900 | - |
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7011Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7011Vendor Advisory
FAQ
What is CVE-2023-20596?
CVE-2023-20596 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.
How severe is CVE-2023-20596?
CVE-2023-20596 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-20596?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 7 5700G Firmware, Amd Ryzen 7 5700G, Amd Ryzen 7 5700Ge Firmware, Amd Ryzen 7 5700Ge, Amd Ryzen 5 5600G Firmware.