Input validation error in AMD Ryzen 3000 Series Desktop processor and AMD Ryzen 5000 Series Desktop processor - CVE-2021-26335
Published: May 26, 2022
Vulnerability identifier: #VU63728
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26335
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input in the AMD Secure Processor (ASP) boot loader image header. A local user can escalate privileges on the system.
Affected software
AMD Ryzen 3000 Series Desktop processor
AMD Ryzen 5000 Series Desktop processor
AMD Ryzen 5000 Series Desktop processor
How to mitigate CVE-2021-26335
Install updates from vendor's website.