A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
History

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in AMD hardware due to a heap overflow in the SMM module. This issue could allow a local unauthenticated attacker to enable writing to SPI flash to execute arbitrary code. A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
Weaknesses CWE-121

cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published: 2026-09-02T19:57:10.678Z

Updated: 2026-09-04T19:56:31.589Z

Reserved: 2022-10-27T18:53:39.757Z

Link: CVE-2023-20577

cve-icon Vulnrichment

Updated: 2026-09-04T19:56:28.556Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T20:17:34.093

Modified: 2026-09-04T20:17:20.570

Link: CVE-2023-20577

cve-icon Redhat

Severity : Important

Publid Date: 2024-02-13T00:00:00Z

Links: CVE-2023-20577 - Bugzilla