Local Privilege Escalation Vulnerability in AMD Products
CVE-2025-48509
1.8LOW
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2025-48509?
A vulnerability exists in AMD products where missing checks in certain functions related to RMP initialization can enable a local administrator with privileged access to manipulate I/O memory. This misidentification may lead to potential threats against the integrity of guest memory, raising significant concerns for system security and stability.
Affected Version(s)
AMD EPYC™ 7003 Series Processors MilanPI 1.0.0.H
AMD EPYC™ 8004 Series Processors GenoaPI 1.0.0.F
AMD EPYC™ 9004 Series Processors GenoaPI 1.0.0.F