Junglewise Threat Intelligence

CVE-2023-20577: AMD firmware heap overflow in SMM module

CVE-2023-20577 · Severity: high · CVSS 7.4 · Published 2026-09-02

Technologies: Amd Firmware. Vendors: Amd.

Executive brief

A memory safety flaw in AMD firmware's System Management Mode (SMM) can be exploited to execute malicious code if an attacker first gains the ability to write to SPI flash memory. Successful exploitation could allow attackers to bypass security protections and gain deep control over affected systems.

Technical details

A heap overflow exists in the SMM (System Management Mode) module of AMD firmware. The vulnerability requires a chained attack: an attacker must first exploit a separate SPI flash write vulnerability to modify firmware, then trigger the heap overflow to execute arbitrary code. Attack vectors include firmware modification and memory corruption. No patch status is specified in the provided advisory data.

Affected products

  • AMD firmware <UNKNOWN>

Timeline

  • 2026-09-02: disclosed

References