Executive brief
A security vulnerability exists in the AMD OverDrive module, a component used for system performance tuning and monitoring. A highly privileged attacker with local access to the system could exploit this flaw to read sensitive information from protected memory areas. This could lead to the exposure of confidential data that is normally restricted by the hardware's security layers.
Technical details
An improper input validation vulnerability exists within the AMD OverDrive (AOD) System Management Mode (SMM) module. The flaw is categorized as an out-of-bounds read (CWE-125) resulting from improper access control for volatile memory (CWE-1274). An attacker with high privileges (such as administrator or SYSTEM) can trigger this vulnerability locally to read memory outside of the intended buffer. This can result in a loss of confidentiality by exposing data residing in SMM, a highly privileged execution environment. AMD has released security bulletins AMD-SB-3030 and AMD-SB-4017 regarding this issue.
Affected products
- AMD OverDrive (AOD) SMM module
Timeline
- 2026-05-15: disclosed: Initial NVD publication date