CVE-2023-20577

A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.

  • Published Sep 2, 2026
  • CVSS 7.4 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2023-20577 at the National Vulnerability Database