CVE-2023-20577: High severity vulnerability
Published Sep 2, 2026
·Updated
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
Event History
Aug 13, 2024
News Published
via The Register·03:14 AM
News Published
via The Register·03:16 AM
Sep 2, 2026
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What additional capability does an attacker need to exploit this issue?
The attacker needs access to a second vulnerability that enables writing to SPI flash. The heap overflow alone is not described as sufficient for exploitation.
2
Is this remotely exploitable?
The provided CVSS vector lists local attack vector (AV:L), so exploitation requires local access rather than network-only access.
3
Does exploitation require an authenticated account or user interaction?
The CVSS vector indicates no privileges required (PR:N) and no user interaction required (UI:N). However, the attacker still needs the separate SPI-flash write capability described in the advisory.