CVE-2023-20584
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Aug 13, 2024
Updated: Aug 14, 2024
Summary
CVE-2023-20584 is a vulnerability affecting IOMMU (Input-Output Memory Management Unit) that mishandles specific special address ranges with invalid device table entries (DTEs). This issue can be exploited by an attacker with privileged access and a compromised hypervisor to induce DTE faults, thereby bypassing RMP (Ring-fencing Memory Protection) checks in SEV-SNP (Secure Enclaves for Secure Nested Paging). The potential consequence of this vulnerability is a loss of guest integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.