Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know
ID: 2decac46-1747-5f37-8f4e-afe57237ded6
STIX ID: report--2decac46-1747-5f37-8f4e-afe57237ded6
Feed Name: Wiz Blog
**Zenbleed (CVE-2023-20593)** — A use-after-free speculative-execution flaw in AMD Zen 2 CPUs allowing local unprivileged code to read privileged memory and leak secrets; affects Ryzen 3000/4000/5000, ThreadRipper 3000, and EPYC Rome, among others. Cloud providers and vendors are releasing microcode/BIOS fixes, and the report recommends ensuring hosts are patched (VM-level fixes are ineffective) and identifying impacted instance types while noting that cloud impact is rated low due to required local code execution and CSP mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
