Insufficient Input Validation in ASP Bootloader Allows for Denial of Service and Integrity Loss

Insufficient Input Validation in ASP Bootloader Allows for Denial of Service and Integrity Loss

CVE-2021-46756 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.

Learn more about our User Device Pen Test.