Improper Input Validation in AmdPspP2CmboxV2 Driver by AMD
CVE-2024-21925
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2024-21925?
The AmdPspP2CmboxV2 driver from AMD contains an improper input validation issue that could allow a privileged attacker to manipulate system memory. By exploiting this vulnerability, an attacker may overwrite SMRAM, leading to potential arbitrary code execution and compromising system integrity. This flaw underscores the importance of rigorous input validation processes in driver development to ensure system security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AMD EPYC™ 7001 Processors Naples PI 1.0.0.N
AMD EPYC™ 7002 Processors Rome PI 1.0.0.K
AMD EPYC™ 7003 Processors Milan PI 1.0.0.E
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved