Executive brief
A security vulnerability exists in certain AMD software components responsible for managing secure operations. If an attacker has already compromised a high-privilege driver, they could potentially access restricted areas of system memory. This could lead to a loss of data integrity, though the attack requires significant existing access to the system.
Technical details
This vulnerability is characterized as an integer overflow (CWE-190) within an AMD Trusted OS (TOS) driver. An attacker who has already compromised a high-privilege driver can issue a malformed call to trigger out-of-bounds memory access. The attack vector is local and requires high privileges (PR:H) and high complexity (AC:H), limiting the practical exploitability. Successful exploitation results in a loss of integrity by allowing access to memory ranges outside of the driver's intended scope. AMD has referenced this in security bulletins AMD-SB-4017 and AMD-SB-6027.
Affected products
- AMD Trusted OS (TOS) Driver
Timeline
- 2026-05-15: advisory: NVD publication date