#VU53292 Code Injection in AMD products - CVE-2020-12967
Published: May 17, 2021 / Updated: March 22, 2022
AMD EPYC Embedded Processors
3rd Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
1st Gen AMD EPYC Processors
AMD
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to the lack of nested page table protection in the AMD SEV/SEV-ES feature. A remote administrator can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.