CVE-2022-23817
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
13/08/2024
Last modified:
15/05/2026
Description
Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
Impact
Base Score 4.0
7.30
Severity 4.0
HIGH
Base Score 3.x
7.00
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-1029.html
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4004.html
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5002.html
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html



