s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-31317

📛 CVE Title

CVE-2023-31317

Description

Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.

Overview

State
PUBLISHED
Assigner (CNA)
AMD
CVSS severity
HIGH
CVSS score
CVSS 8.8 / 10 8.8 8.8 / 10
CVSS vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Effective score
8.8 / 10 HIGH source: CNA overview
CWE(s)
CWE-119
Reserved
2023-04-27
Published
2026-05-15 04:47 UTC
Last updated
2026-05-16 05:56 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/31xxx/CVE-2023-31317.json
Linked Threat
CVE-2023-31317 — CVE-2023-31317

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-35628
Assigner
AMD
Published
May 15, 2026, 2:47:12 AM
Updated
May 16, 2026, 3:56:15 AM
EUVD base score (CVSS 4.0)
8.8 / 10
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EUVD-reported EPSS
0.0200
Vendors
AMD
Products
AMD Radeon™ RX 6000 Series Graphics Products (patch: AMD Software: Adrenalin Edition 25.11.1 (25.10.33.03))
AMD Instinct™ MI250 (patch: ROCm 7.0)
AMD Instinct™ MI210 (patch: ROCm 7.0)
AMD Radeon™ RX 7000 Series Graphics Products (patch: AMD Software: Adrenalin Edition 25.11.1 (25.20.29.01))
AMD Radeon™ PRO W6000 Series Graphics Products (patch: AMD Software: PRO Edition 25.Q3.1 (25.10.32))
AMD Radeon™ PRO W7000 Series Graphics Products (patch: AMD Software: PRO Edition 25.Q3.1 (25.10.32))
Aliases
GHSA-j9fg-4xxv-qcp6

ENISA description: Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.

EUVD references (1)

Affected products (6)

VendorProductVersionsPlatforms
AMD AMD Radeon™ RX 6000 Series Graphics Products AMD Software: Adrenalin Edition 25.11.1 (25.10.33.03) (unaffected)
AMD AMD Radeon™ RX 7000 Series Graphics Products AMD Software: Adrenalin Edition 25.11.1 (25.20.29.01) (unaffected)
AMD AMD Radeon™ PRO W7000 Series Graphics Products AMD Software: PRO Edition 25.Q3.1 (25.10.32) (unaffected)
AMD AMD Radeon™ PRO W6000 Series Graphics Products AMD Software: PRO Edition 25.Q3.1 (25.10.32) (unaffected)
AMD AMD Instinct™ MI250 ROCm 7.0 (unaffected)
AMD AMD Instinct™ MI210 ROCm 7.0 (unaffected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

MITRE references (1) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (3)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (20)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:github.com

    CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes

    2026-06-13 07:01 UTC
  • web:www.microsoft.com

    Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.

    2026-06-13 07:01 UTC
  • web:www.oracle.com

    Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

    2026-06-13 07:01 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.

    2026-06-13 07:01 UTC
  • web:github.com

    shiversoftdev's t7patch, updated to work with the Feb 2026 game update. - GitHub - Scroptss/T7Patch: shiversoftdev's t7patch, updated to work with the Feb 2026 game update.

    2026-06-13 07:01 UTC
  • web:www.hipaajournal.com

    CISA's solution is to patch smarter, not harder. CISA has released a new risk-based vulnerability remediation framework to help vendors assess vulnerabilities and prioritize patching effectively, concentrating their efforts on mitigating vulnerabilities in the most at-risk assets and addressing vulnerabilities that carry the greatest risk of ...

    2026-06-13 07:01 UTC
  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

    2026-05-22 06:28 UTC
  • web:www.bleepingcomputer.com

    Microsoft has released an out-of-band (OOB) update to fix a security vulnerabilities affecting Windows 11 Enterprise devices that receive hotpatch updates instead of the regular Patch Tuesday ...

    2026-05-22 06:28 UTC
  • web:www.pcworld.com

    This month's Patch Tuesday includes an actively exploited Office zero-day vulnerability and several critical RCE bugs in Windows and Remote Desktop.

    2026-05-22 06:28 UTC
  • web:attack.mitre.org

    This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...

    2026-05-22 06:28 UTC
  • web:www.zdnet.com

    Why you need Microsoft's new emergency Windows patch - and the black-screen bug to watch for While Microsoft has been fixing bugs caused by the Patch Tuesday update, another glitch has surfaced.

    2026-05-22 03:23 UTC
  • web:cybersecuritynews.com

    Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.

    2026-05-22 03:23 UTC
  • web:krebsonsecurity.com

    Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.

    2026-05-22 03:23 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-05-22 03:23 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 03:23 UTC
  • web:www.bleepingcomputer.com

    Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates.

    2026-05-22 03:23 UTC
  • web:www.cisa.gov

    Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287

    2026-05-22 03:23 UTC
  • web:www.computerworld.com

    Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

    2026-05-22 03:23 UTC
  • web:www.experts-exchange.com

    Learn more about Resolving Sweet32, Birthday Attacks on Windows Servers Via GPO from the expert community at Experts Exchange

    2026-05-22 03:23 UTC
  • web:www.techrepublic.com

    Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.

    2026-05-22 03:23 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2023-31317.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-31317",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-15T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-16T03:56:15.164Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "AMD Radeon\u2122 RX 6000 Series Graphics Products",
          "vendor": "AMD",
          "versions": [
            {
              "status": "unaffected",
              "version": "AMD Software: Adrenalin Edition 25.11.1 (25.10.33.03)"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "AMD Radeon\u2122 RX 7000 Series Graphics Products",
          "vendor": "AMD",
          "versions": [
            {
              "status": "unaffected",
              "version": "AMD Software: Adrenalin Edition 25.11.1 (25.20.29.01)"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "AMD Radeon\u2122 PRO W7000 Series Graphics Products",
          "vendor": "AMD",
          "versions": [
            {
              "status": "unaffected",
              "version": "AMD Software: PRO Edition 25.Q3.1 (25.10.32)"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "AMD Radeon\u2122 PRO W6000 Series Graphics Products",
          "vendor": "AMD",
          "versions": [
            {
              "status": "unaffected",
              "version": "AMD Software: PRO Edition 25.Q3.1 (25.10.32)"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "AMD Instinct\u2122 MI250",
          "vendor": "AMD",
          "versions": [
            {
              "status": "unaffected",
              "version": "ROCm 7.0"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "AMD Instinct\u2122 MI210",
          "vendor": "AMD",
          "versions": [
            {
              "status": "unaffected",
              "version": "ROCm 7.0"
            }
          ]
        }
      ],
      "datePublic": "2026-05-15T02:41:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.<br>"
            }
          ],
          "value": "Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-119",
              "description": "CWE-119  Improper Restriction of Operations within the Bounds of a Memory Buffer",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-15T02:47:39.059Z",
        "orgId": "b58fc414-a1e4-4f92-9d70-1add41838648",
        "shortName": "AMD"
      },
      "references": [
        {
          "url": "https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "AMD PSIRT Automation 1.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b58fc414-a1e4-4f92-9d70-1add41838648",
    "assignerShortName": "AMD",
    "cveId": "CVE-2023-31317",
    "datePublished": "2026-05-15T02:47:12.434Z",
    "dateReserved": "2023-04-27T15:25:41.423Z",
    "dateUpdated": "2026-05-16T03:56:15.164Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}