LiveActive security incident?Get immediate response
CVE Record

CVE-2021-26366: An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boo...

An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This AMD issue could let an attacker who already has elevated privileges read Boot ROM data, undermining system integrity. The public record lists various Ryzen and Athlon systems, but does not provide CVSS scoring or detailed affected model coverage in the bundle.

Executive priority

Treat this as a firmware integrity risk requiring inventory and vendor-advisory follow-up, not as an emergency internet-facing exposure based on the provided evidence.

Technical view

CVE-2021-26366 concerns Boot ROM data exposure after an attacker has already obtained elevated privileges through another vulnerability. The stated impact is loss of system integrity. Available sources identify AMD Ryzen Series and Athlon Series as affected in various versions, with AMD SB-1027 as the vendor reference.

Likely exposure

Exposure is most likely on assets using AMD Ryzen or Athlon processors covered by AMD SB-1027. Exact exposure depends on processor model, platform firmware, and OEM update status, which are not fully detailed in the provided bundle.

Exploitation context

The source states exploitation requires elevated privileges gained through another vulnerability. The bundle does not cite public exploitation, and KEV status is false, so active exploitation should not be asserted.

Researcher notes

The record is sparse: no CVSS, CWE, exploit evidence, or detailed fixed versions are included in the bundle. The key constraint is that elevated privileges are prerequisite, so validation should focus on platform matching and firmware status.

Mitigation direction

  • Review AMD SB-1027 and applicable OEM firmware guidance.
  • Inventory systems using AMD Ryzen and Athlon processors.
  • Apply vendor-provided BIOS or firmware updates where available.
  • Prioritize systems handling sensitive workloads or privileged access.
  • Reduce privilege-escalation risk through normal OS and firmware patching.

Validation and detection

  • Map processor models against AMD SB-1027 affected-product guidance.
  • Check BIOS and firmware versions against OEM advisory pages.
  • Confirm whether vulnerable Ryzen or Athlon systems remain in production.
  • Review endpoint posture for unresolved privilege-escalation weaknesses.
  • Document exceptions where vendor firmware is unavailable.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-26366 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AMDRyzen™ SeriesvariousListed
AMDAthlon™ SeriesvariousListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.