CVE-2021-46747
Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-1220
- Published
- 2026-06-01
- Last modified
- 2026-06-02
Affected products
- AMD AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics
- AMD AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors
- AMD AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors
- AMD AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics
- AMD AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors
- AMD AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics
Weakness type
Related vulnerabilities
- CVE-2026-77480 — SQL Server Elevation of Privilege Vulnerability
- CVE-2026-66814 — Microsoft SQL Server Elevation of Privilege Vulnerability
- CVE-2026-69267 — Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability
- CVE-2026-78216 — AshLua eval read operations can read field-policy-protected fields via aggregates
- CVE-2026-78230 — AshAi aggregate tool can read field-policy-protected fields
- CVE-2026-15431 — HP Support Assistant – Potential Escalation of Privilege
- CVE-2026-78122 — docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
- CVE-2026-40145 — Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility