CVE-2020-12890: AMD Generic Encapsulated Software Architecture

Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.

Affected products

  • AMD AMD Generic Encapsulated Software Architecture: affected versions not specified

Published 2021-12-10. Last modified 2026-06-17.