CVE-2023-31315
HIGH EPSS 45.3%
Published Aug 12, 20241y ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
Published Aug 12, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector Local
Attack Complexity High
Privileges Required High
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
45.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-94 Improper Control of Generation of Code (Code Injection) Injection
References 4
- media.defcon.org https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Enrique%20Nissim%20Krzysztof%20Okupski%20-%20AMD%20Sinkclose%20Universal%20Ring-2%20Privilege%20Escalation.pdf
- news.ycombinator.com https://news.ycombinator.com/item?id=41475975
- amd.com https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html
- darkreading.com https://www.darkreading.com/remote-workforce/amd-issues-updates-for-silicon-level-sinkclose-flaw
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.