Improper access control in AMD products - CVE-2021-26387
Published: October 2, 2024
1st Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
4th Gen AMD EPYC Processors
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in ASP kernel. A local privileged user with access to AMD signing keys and the BIOS menu or UEFI shell can map DRAM regions in protected areas.
How to mitigate CVE-2021-26387
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
The vendor is not planning to release security fixes to address this vulnerability.