Executive brief
A vulnerability in the AMD Secure Processor could allow an attacker to interfere with how the system handles power-saving transitions. By exploiting this flaw, a local user with specific access could manipulate the video processing firmware, potentially leading to unauthorized access to data or system instability. This impacts the fundamental security layer designed to protect sensitive hardware configurations during sleep or low-power modes.
Technical details
The vulnerability is classified as CWE-1304, involving the improper preservation of hardware configuration state integrity during power save/restore cycles within the AMD Secure Processor (ASP). An attacker who already possesses the capability to write outside the Trusted Memory Range (TMR) can exploit this state-handling flaw to redirect or modify the execution flow of the Video Core Next (VCN) firmware. This is a local attack requiring low privileges but high complexity and specific preconditions. Successful exploitation could compromise the confidentiality and integrity of the secure environment. AMD has addressed this in security bulletins AMD-SB-4017 and AMD-SB-6027.
Affected products
- AMD Secure Processor (ASP)
- AMD Video Core Next (VCN) firmware
Timeline
- 2026-05-15: advisory: NVD publication date