CVE-2024-36355

Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Validación de entrada incorrecta en el controlador SMM podría permitir a un atacante con acceso Ring0 escribir en la SMRAM y modificar el flujo de ejecución para el despertar de S3 (suspensión), resultando potencialmente en ejecución de código arbitrario.

12 Feb 2026, 18:16

Type Values Removed Values Added
References
  • {'url': 'https://www.amd.com/en/resources/product-security/bulletin/Emb-Auto.html', 'source': 'psirt@amd.com'}

10 Feb 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 20:16

Updated : 2026-06-17 07:36


NVD link : CVE-2024-36355

Mitre link : CVE-2024-36355

CVE.ORG link : CVE-2024-36355


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write