Executive brief
A vulnerability in the AMD Secure Processor (ASP) could allow an attacker with local access to bypass security protections. The ASP is a dedicated security chip integrated into AMD processors that handles sensitive tasks like encryption and secure boot. If exploited, this flaw could allow an attacker to read or modify protected memory, potentially leading to a full system takeover or the theft of sensitive data.
Technical details
This vulnerability is classified as a memory buffer overflow (CWE-119) within the AMD Secure Processor (ASP) firmware. The flaw stems from improper restriction of operations within the bounds of a memory buffer. An attacker with local access and low privileges could exploit this to perform unauthorized read or write operations on protected memory regions. Successful exploitation could lead to arbitrary code execution within the context of the ASP, effectively compromising the hardware-based Root of Trust. The attack requires high complexity (AC:H) but can result in a total loss of confidentiality, integrity, and availability across both the local and virtualized environments.
Affected products
- AMD Secure Processor (ASP)
Timeline
- 2026-05-15: disclosed: NVD publication date