Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 23 Sep 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-20 | 
Tue, 23 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-1231 | 
Mon, 08 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Amd Amd athlon Amd athlon 3000 Amd epyc Amd epyc 4004 Amd epyc 7001 Amd epyc 7002 Amd epyc 7003 Amd epyc 8004 Amd epyc 9004 Amd epyc Embedded 3000 Amd epyc Embedded 7002 | |
| Vendors & Products | Amd Amd athlon Amd athlon 3000 Amd epyc Amd epyc 4004 Amd epyc 7001 Amd epyc 7002 Amd epyc 7003 Amd epyc 8004 Amd epyc 9004 Amd epyc Embedded 3000 Amd epyc Embedded 7002 | 
Mon, 08 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sat, 06 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level. | |
| Weaknesses | CWE-20 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: AMD
Published: 2025-09-06T18:06:43.084Z
Updated: 2025-09-23T21:26:51.266Z
Reserved: 2024-05-23T19:44:50.000Z
Link: CVE-2024-36354
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-09-08T14:36:03.042Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-09-06T18:15:40.297
Modified: 2025-09-23T22:15:33.817
Link: CVE-2024-36354
 Redhat
                        Redhat
                    No data.