Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS (SMM modules): An SMM vulnerability letting a privileged local attacker execute arbitrary code
Impact
An SMM vulnerability letting a privileged local attacker execute arbitrary code in System Management Mode, manipulate SMM stack memory, and leak SMRAM contents into kernel space. SMRAM is supposed to be opaque to the OS; leaking it hands the attacker firmware secrets and the layout information needed to build a reliable bootkit. Once code runs in SMM the attacker is above the hypervisor and can survive OS reinstall, so a node that was compromised once should be considered compromised until its firmware is reflashed and verified, not just reimaged.
Who can reach it
Local, low privileges required per AMI's CVSS vector, no user interaction. Needs code on the host - which on any node running untrusted tenant workloads or on any node after an initial OS compromise is a given.
What to do
BIOS update from your server vendor carrying the fixed AptioV build - firmware flash plus a full host reboot, per node. AMI's advisory names only 'AptioV' as the fix version rather than a specific BKC, so you must confirm with your OEM which BIOS release for your SKU actually contains it; do not assume 'latest' covers it. No config-only mitigation for an SMM bug.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.