CVE-2022-23817

Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
CVSS

No CVSS.

Configurations

No configuration.

History

15 May 2026, 05:16

Type Values Removed Values Added
CWE CWE-20
Summary (en) Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation. (en) Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
CVSS v2 : unknown
v3 : 7.0
v2 : unknown
v3 : unknown
References
  • {'url': 'https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4004.html', 'source': 'psirt@amd.com'}
  • () https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-1029.html -
  • () https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4004.html -
  • () https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5002.html -
  • () https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html -

16 Aug 2024, 21:35

Type Values Removed Values Added
CWE CWE-120
Summary
  • (es) Una comprobación insuficiente del búfer de memoria en ASP Secure OS puede permitir que un atacante con un TA malicioso lea/escriba en el espacio de direcciones virtuales del kernel de ASP Secure OS, lo que podría provocar una escalada de privilegios.

13 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 17:15

Updated : 2026-05-15 05:16


NVD link : CVE-2022-23817

Mitre link : CVE-2022-23817

CVE.ORG link : CVE-2022-23817


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')