CVE-2018-8936: Critical severity AMD Ryzen Mobile Firmware vulnerability
Published Mar 22, 2018
·Updated
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
Affected Software
16 affected components
AMD Ryzen Mobile Firmware
AMD Ryzen Mobile
AMD Ryzen Pro Firmware
AMD Ryzen Pro
AMD Epyc Server Firmware
AMD EPYC Server
AMD Ryzen Firmware
AMD Ryzen
All of the following
AMD Ryzen Mobile Firmware
AMD Ryzen Mobile
All of the following
AMD Ryzen Pro Firmware
AMD Ryzen Pro
All of the following
AMD Epyc Server Firmware
AMD EPYC Server
All of the following
AMD Ryzen Firmware
AMD Ryzen
Event History
Mar 22, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8936?
CVE-2018-8936 is classified as a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2018-8936?
To fix CVE-2018-8936, users should update their AMD firmware to the latest versions provided by AMD.
3
Which AMD products are affected by CVE-2018-8936?
CVE-2018-8936 affects AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processors.
4
What consequences can arise from CVE-2018-8936?
CVE-2018-8936 can lead to unauthorized access and control over the affected systems due to privilege escalation.
5
Is there any public information available about CVE-2018-8936?
Yes, public information about CVE-2018-8936 can be found in various security advisories and technical blogs.