VYPR

System Management Mode

by AMD

CVEs (5)

  • CVE-2024-21947HigSep 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at the SMM level.

  • CVE-2025-29950HigFeb 10, 2026
    risk 0.46cvss —epss 0.00

    Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution.

  • CVE-2025-0012MedFeb 10, 2026
    risk 0.44cvss —epss 0.00

    Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality.

  • CVE-2026-0438MedMay 15, 2026
    risk 0.35cvss —epss 0.00

    A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM,…

  • CVE-2024-36343MedMay 19, 2026
    risk 0.30cvss —epss 0.00

    Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of…