Improper Input Validation in AMD Platform Management Framework Driver
CVE-2025-48520

6.9MEDIUM

What is CVE-2025-48520?

The AMD Platform Management Framework (PMF) driver contains an improper input validation vulnerability that enables local attackers to exploit out-of-bounds scenarios. This flaw may lead to unauthorized information disclosure or even cause system crashes, jeopardizing the integrity and availability of affected systems. Proper validation mechanisms should be implemented to mitigate potential risks associated with this vulnerability.

Affected Version(s)

AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt") 7.06.02.123

AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R") 7.06.02.123

AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix") 7.06.02.123

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.