CVE-2023-31355: exploitation status and patch state
CVE-2023-31355 · CVSS 6.0 MEDIUM · EPSS <1%
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
Is CVE-2023-31355 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.