Executive brief
A vulnerability exists in the driver for the AMD Secure Processor, a hardware component responsible for managing security functions on AMD-based computers. A local attacker with low-level access to the system could exploit this flaw to cause a system crash or a denial of service. This could disrupt business operations by forcing affected machines to restart or become unresponsive.
Technical details
A classic buffer overflow (CWE-120) exists in the AMD Secure Processor (ASP) PCI driver due to improper input validation. A local attacker with low privileges (PR:L) can trigger this condition by providing specially crafted input to the driver. Successful exploitation can lead to a buffer overflow, resulting in a system crash or a denial-of-service (DoS) state. The vulnerability is tracked under AMD security bulletins AMD-SB-3047 and AMD-SB-4015.
Affected products
- AMD Secure Processor (ASP) PCI driver
Timeline
- 2026-05-15: advisory: NVD publication date