Exposure of Uninitialized Resources in AMD Platform Management Framework
CVE-2025-48513

6.9MEDIUM

What is CVE-2025-48513?

The AMD Platform Management Framework has a vulnerability that arises from the use of uninitialized resources. This flaw could enable attackers to access sensitive information stored in uninitialized kernel memory, posing risks to the confidentiality and availability of the system. It is crucial for users to be aware of this vulnerability and apply any necessary updates or patches to safeguard their systems against potential exploitation.

Affected Version(s)

AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt") 7.06.02.123

AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R") 7.06.02.123

AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix") 7.06.02.123

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.