Local Attack Vulnerability in AMD uProf for Enhanced Security Measures
CVE-2025-48510

7.1HIGH

Key Information:

Vendor

Amd

Vendor
CVE Published:
24 November 2025

What is CVE-2025-48510?

A vulnerability in AMD uProf has been identified that allows a local attacker to exploit an improper return value. This flaw can result in a bypass of Kernel Address Space Layout Randomization (KSLR), which may lead to significant risks regarding system confidentiality and availability. Users of AMD uProf are advised to review their security practices to mitigate any potential risks from this vulnerability.

Affected Version(s)

AMD μProf 5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.
CVE-2025-48510 : Local Attack Vulnerability in AMD uProf for Enhanced Security Measures