CVE-2020-12966: Infoleak
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by the malicious hypervisor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12966?
CVE-2020-12966 is classified as a medium severity information disclosure vulnerability in AMD EPYC processors.
How do I fix CVE-2020-12966?
To fix CVE-2020-12966, update the firmware to versions later than milanpi-sp3_1.0.0.5 for affected AMD EPYC processors.
Who is affected by CVE-2020-12966?
CVE-2020-12966 affects AMD EPYC processors utilizing Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Nested Paging (SEV-SNP).
What could an attacker do with CVE-2020-12966?
A local authenticated attacker could potentially exploit CVE-2020-12966 to disclose sensitive information within the secure environment of the AMD EPYC processor.
When was CVE-2020-12966 disclosed?
CVE-2020-12966 was disclosed on August 8, 2022, in a forum on OSS Security.