Vulnerabilities > CVE-2021-26344 - Out-of-bounds Write vulnerability in AMD products

047910
CVSS 8.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
amd
CWE-787

Summary

An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

Vulnerable Configurations

Part Description Count
OS
Amd
278
Hardware
Amd
69

Common Weakness Enumeration (CWE)