CVE-2017-7563: Trustedfirmware Trusted Firmware-A

High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).

Affected products

Published 2017-06-07. Last modified 2026-06-17.