Junglewise Threat Intelligence

CVE-2021-46747: AMD Secure Processor privilege escalation via insufficient SMN access control

CVE-2021-46747 · Severity: info · CVSS 7.1 · Published 2026-06-01

Technologies: Amd Secure Processor. Vendors: Amd.

Executive brief

A security flaw in the AMD Secure Processor, a dedicated security chip within AMD processors, could allow a malicious user with high-level system access to bypass certain security boundaries. By exploiting improper access controls, an attacker could gain unauthorized access to sensitive internal management networks. This could lead to a full escalation of privileges, potentially allowing the attacker to compromise the entire system's integrity and data.

Technical details

This vulnerability is classified as insufficient granularity of access control (CWE-1220) within the AMD Secure Processor (ASP). The flaw resides in how the ASP manages access to the System Management Network (SMN) apertures. A local attacker running an untrusted user-space application with high privileges could exploit this lack of granularity to map sensitive SMN regions that should otherwise be restricted. Successful exploitation allows for unauthorized access to internal hardware communication channels, potentially resulting in a complete escalation of privileges and compromise of the host environment. AMD has addressed this issue in security bulletins AMD-SB-4017 and AMD-SB-6027.

Affected products

  • AMD Secure Processor (ASP)

Timeline

  • 2026-06-01: advisory: NVD publication date

References

Related threats