CVE-2023-31355
MEDIUMAMD EPYC 7003 Series Firmware < milanpi_1.0.0.d - Memory Read via UMC Seed Overwrite
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-31355. PoCs published by Freax13.
AI-analyzed exploit summary This PoC exploits a vulnerability in AMD SEV firmware (CVE-2023-31355) by corrupting the UMC key seed to decrypt arbitrary memory of an SEV-SNP guest after decommissioning. The exploit leverages uninitialized RMP entries to overwrite the key seed at address 0.
Description
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
Exploits (1)
This PoC exploits a vulnerability in AMD SEV firmware (CVE-2023-31355) by corrupting the UMC key seed to decrypt arbitrary memory of an SEV-SNP guest after decommissioning. The exploit leverages uninitialized RMP entries to overwrite the key seed at address 0.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N