CVE-2024-36354

HIGH

AMD Processors - Arbitrary Code Execution via DIMM SPD Metadata

Title source: llm
STIX 2.1

Description

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1231
Status published
Products (38)
AMD/AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics ComboAM4PI_1.0.0.C
AMD/AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics PicassoPI-FP5_1.0.1.2a
AMD/AMD EPYC™ 4004 Series Processors ComboAM5PI_1.2.0.2a
AMD/AMD EPYC™ 7001 Series Processors Naples 1.0.0.Q
AMD/AMD EPYC™ 7002 Series Processors Rome PI 1.0.0.M
AMD/AMD EPYC™ 7003 Series Processors MilanPI 1.0.0.D
AMD/AMD EPYC™ 8004 Series Processors GenoaPI 1.0.0.D
AMD/AMD EPYC™ 9004 Series Processors GenoaPI 1.0.0.D
AMD/AMD EPYC™ Embedded 3000 Series Processors SnowyOwl PI 1.1.0.F
AMD/AMD EPYC™ Embedded 7002 Series Processors EmbRomePI-SP3_1.0.0.E
... and 28 more
Published Sep 06, 2025
Tracked Since Feb 18, 2026