Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution.
A side channel attack known as ‘Inception’ or ‘RAS Poisoning’ may allow an attacker to influence branch prediction, potentially leading to information disclosure.
Refer: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7005.html