AMDCVE-2023-20577
AMD: code execution
High7.4CVE-2023-20577 · Published Sep 2, 2026 · updated Sep 4, 2026
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-121
More AMD advisories
All AMD| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | AMD AGESA: denial of service | High7.7 | No fix yet |
| Aug 31 | AMD: double free | Medium6.4 | No fix yet |
| Aug 31 | AMD: denial of service | Low3.3 | No fix yet |
| Aug 11 | AMD: privilege escalation | High7.0 | No fix yet |
| Aug 11 | AMD: untrusted search path | High7.0 | No fix yet |
| Aug 11 | AMD Ryzen Master Utility Driver: use after free | Medium5.6 | No fix yet |