CVE-2018-8936
UnknownEPSS 1.81%
Last modified
CVE-2018-8936 is a vulnerability of currently unknown severity. The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen Mobile Firmware | All versions |
| Amd | Ryzen Pro Firmware | All versions |
| Amd | Epyc Server Firmware | All versions |
| Amd | Ryzen Firmware | All versions |
References
- https://amdflaws.com/Third Party Advisory
- https://blog.trailofbits.com/2018/03/15/amd-flaws-technical-summary/Third Party Advisory
- https://safefirmware.com/amdflaws_whitepaper.pdfThird Party Advisory
- https://amdflaws.com/Third Party Advisory
- https://blog.trailofbits.com/2018/03/15/amd-flaws-technical-summary/Third Party Advisory
- https://safefirmware.com/amdflaws_whitepaper.pdfThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8936?
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
How severe is CVE-2018-8936?
Severity scoring for CVE-2018-8936 is pending analysis. The EPSS model estimates a 1.81% probability of exploitation in the next 30 days.
How do I fix CVE-2018-8936?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-8930The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile proc…
- CVE-2018-8931The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips h…
- CVE-2018-8932The AMD Ryzen and Ryzen Pro processor chips have insufficien…
- CVE-2018-8933The AMD EPYC Server processor chips have insufficient access…
- CVE-2018-8934The Promontory chipset, as used in AMD Ryzen and Ryzen Pro p…
- CVE-2018-8935The Promontory chipset, as used in AMD Ryzen and Ryzen Pro p…
- CVE-2018-8937An issue was discovered in Open-AudIT Professional 2.1. It i…
- CVE-2018-8938A Code Injection issue was discovered in DlgSelectMibFile.as…
- CVE-2018-8939An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsU…
- CVE-2018-8940ClientServiceConfigController.cs in Enghouse Cloud Contact C…
- CVE-2018-8941Diagnostics functionality on D-Link DSL-3782 devices with fi…
- CVE-2018-8942Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.
Are you affected by CVE-2018-8936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
