CVE-2024-21980
HIGHAMD EPYC 7003 Series Firmware < milanpi_1.0.0.d - Memory Corruption via SNP Firmware Write Operations
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-21980. PoCs published by Freax13.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-21980, a vulnerability in AMD SEV firmware that allows decrypting arbitrary memory of an SEV-SNP guest after decommissioning. The exploit leverages a missing enforcement check in the `SEV_MCMD_ID_ATTESTATION` command to corrupt memory and force a static UMC key seed.
Description
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
Exploits (1)
This repository contains a functional exploit for CVE-2024-21980, a vulnerability in AMD SEV firmware that allows decrypting arbitrary memory of an SEV-SNP guest after decommissioning. The exploit leverages a missing enforcement check in the `SEV_MCMD_ID_ATTESTATION` command to corrupt memory and force a static UMC key seed.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N