Unchecked Return Value Vulnerability in AMD Platform Management Framework
CVE-2025-0028

8.3HIGH

What is CVE-2025-0028?

The AMD Platform Management Framework (PMF) contains a vulnerability stemming from an unchecked return value. This flaw allows an attacker to potentially read or modify arbitrary memory addresses, posing significant risks to the confidentiality, integrity, and availability of data. Exploitations of this vulnerability could lead to unauthorized access and manipulation of sensitive information, highlighting the importance of immediate remediation and updates to affected systems.

Affected Version(s)

AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt") 7.06.02.123

AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R") 7.06.02.123

AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix") 7.06.02.123

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.