CVE-2023-31315: AMD 1st Gen AMD Epyc Processors

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

Affected products

  • AMD 1st Gen AMD Epyc Processors
  • AMD 2nd Gen AMD Epyc Processors
  • AMD 3rd Gen AMD Epyc Processors
  • AMD 4th Gen AMD Epyc Processors
  • AMD AMD Athlon 3000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Epyc Embedded 3000
  • AMD AMD Epyc Embedded 7002
  • AMD AMD Epyc Embedded 7003
  • AMD AMD Epyc Embedded 9003
  • AMD AMD Ryzen 3000 Series Desktop Processors
  • AMD AMD Ryzen 3000 Series Mobile Processor With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processor With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processors
  • AMD AMD Ryzen 5000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 6000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7000 Series Desktop Processors
  • AMD AMD Ryzen 7020 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7030 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 7035 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7040 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 7045 Series Mobile Processors
  • AMD AMD Ryzen 8000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen Embedded 5000
  • and 39 more

Published 2024-08-12. Last modified 2026-06-17.