CVE-2021-39298
Summary
| CVE | CVE-2021-39298 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-16 17:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1027 | MISC | www.amd.com | |
| HP UEFI Firmware February 2022 Security Updates | HP® Customer Support | MISC | support.hp.com | |
| www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032 | MISC | www.amd.com | |
| www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027 | MISC | www.amd.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.