Junglewise Threat Intelligence

CVE-2025-0028: AMD Platform Management Framework unchecked return value

CVE-2025-0028 · Severity: info · CVSS 8.3 · Published 2026-05-15

Technologies: Amd Platform Management Framework. Vendors: Amd.

Executive brief

A vulnerability exists in the AMD Platform Management Framework, a component responsible for managing system performance and power settings. An attacker with local access to the system could exploit this flaw to read or modify sensitive memory locations. This could lead to the theft of confidential information, system instability, or a complete loss of control over the affected device.

Technical details

A vulnerability classified as CWE-252 (Unchecked Return Value) exists within the AMD Platform Management Framework (PMF). The flaw occurs when the software fails to validate the return value of a function call, which can be leveraged by a local attacker with low privileges to perform arbitrary memory reads or writes. Successful exploitation could allow an attacker to bypass security boundaries, access sensitive data in memory, or cause a denial-of-service condition. The attack requires local access but no user interaction. AMD has addressed this issue in security bulletin AMD-SB-4015.

Affected products

  • AMD Platform Management Framework (PMF)

Timeline

  • 2026-05-15: disclosed: Initial NVD publication date
  • 2026-05-14: advisory: AMD security bulletin AMD-SB-4015 released

References

Related threats