First published: Thu May 13 2021(Updated: )
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD EPYC 7232p firmware | ||
AMD EPYC 7251 | ||
AMD EPYC 7252 Firmware | ||
AMD Epyc 7261 | ||
AMD EPYC 7262 Firmware | ||
AMD EPYC 7272 firmware | ||
AMD EPYC 7281 Firmware | ||
AMD EPYC 7282 | ||
AMD EPYC 72F3 Firmware | ||
AMD EPYC 7301 Firmware | ||
AMD EPYC 7302P | ||
AMD EPYC 7302P | ||
AMD EPYC 7313P | ||
AMD EPYC 7313P | ||
AMD EPYC 7343 | ||
AMD EPYC 7351P Firmware | ||
AMD EPYC 7351P Firmware | ||
AMD EPYC 7352 | ||
AMD EPYC 7371 Firmware | ||
AMD EPYC 73F3 | ||
AMD EPYC 7401 | ||
AMD EPYC 7401P | ||
AMD EPYC 7402 | ||
AMD EPYC 7402P | ||
AMD EPYC 7413 Firmware | ||
AMD EPYC 7443 | ||
AMD EPYC 7443P | ||
AMD EPYC 7451 Firmware | ||
AMD EPYC 7452 | ||
AMD EPYC 7453 | ||
AMD EPYC 74F3 | ||
AMD EPYC 7501 | ||
AMD EPYC 7502 | ||
AMD EPYC 7502P | ||
AMD EPYC 7513 | ||
AMD EPYC 7532 | ||
AMD EPYC 7542 | ||
AMD EPYC 7543 Firmware | ||
AMD EPYC 7543P Firmware | ||
AMD EPYC 7551 Firmware | ||
AMD EPYC 7551P Firmware | ||
AMD EPYC Embedded 7552 | ||
AMD EPYC 75F3 | ||
AMD EPYC 7601 Firmware | ||
AMD EPYC 7642 Firmware | ||
AMD EPYC 7643 | ||
AMD EPYC 7662 | ||
AMD EPYC 7663 Firmware | ||
AMD EPYC 7702 | ||
AMD EPYC 7702p | ||
AMD EPYC 7713 | ||
AMD EPYC 7713P Firmware | ||
AMD EPYC 7742 firmware | ||
AMD EPYC 7763 Firmware | ||
AMD EPYC 7F32 Firmware | ||
AMD EPYC 7F52 | ||
AMD EPYC 7F72 | ||
AMD EPYC 7H12 | ||
AMD EPYC Embedded 3101 | ||
AMD EPYC Embedded 3151 | ||
AMD EPYC Embedded 3201 | ||
AMD EPYC Embedded 3251 | ||
AMD EPYC Embedded 3255 | ||
AMD EPYC Embedded 3351 Firmware | ||
AMD EPYC Embedded 3451 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12967 is a vulnerability in the AMD SEV/SEV-ES feature that allows arbitrary code execution within the guest VM.
The lack of nested page table protection can be exploited by a malicious administrator who has access to compromise the server hypervisor.
CVE-2020-12967 has a severity rating of critical.
The software products affected by CVE-2020-12967 include AMD Epyc processors and Microsoft Windows 11.
You can find more information about CVE-2020-12967 on the AMD Product Security Bulletin website.