216.73.217.22

CVE-2026-0438

· Published 15/05/2026 02:16 · Modified 15/05/2026 14:10

Labels: CVE-2026-0438 2026-05-15CVE-2026-0438CWE-1072[email protected]

Essential information

Published
15/05/2026 02:16
Modified
15/05/2026 14:10
Author
Creator
CVSS
5.4 MEDIUM (v3) 5.4 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM, potentially compromising the system’s confidentiality, integrity, and availability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
amd / smm cpe:2.3:a:amd:smm:*:*:*:*:*:*:*:*

References