Skip to main content

Improper Access Control for Volatile Memory Containing Boot Code

CVE-2024-36345

Severity Medium
Score 4.6/10

Summary

Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.

  • LOW
  • LOCAL
  • NONE
  • HIGH

CWE-1274 - Improper Access Control for Volatile Memory Containing Boot Code

The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.

References

Advisory Timeline

  • Published