CVE-2024-36355
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Publication date: 2026-02-10
Last updated on: 2026-02-12
Assigner: Advanced Micro Devices Inc.
Description
Description
Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | epyc | * |
| amd | athlon | * |
| amd | ryzen | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |