Junglewise Threat Intelligence

CVE-2025-29935: AMD Platform Management Framework out of bounds write

CVE-2025-29935 · Severity: info · CVSS 8.4 · Published 2026-05-15

Technologies: Amd Platform Management Framework. Vendors: Amd.

Executive brief

A security vulnerability has been identified in the AMD Platform Management Framework, which is responsible for managing system power, thermal, and performance settings. An attacker with low-level access to a system could exploit this flaw to gain full control over the device. This could lead to the theft of sensitive data, system instability, or the installation of persistent malicious software.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists within the AMD Platform Management Framework (PMF). The flaw is triggered when the framework improperly handles memory writes, allowing data to be written outside of intended buffer boundaries. A local attacker with low privileges (PR:L) can exploit this to achieve arbitrary code execution at an elevated privilege level. This impact extends beyond the immediate software component to the underlying system security state (SC:H/SI:H/SA:H). Users are advised to refer to AMD security bulletin AMD-SB-4015 for specific firmware update availability.

Affected products

  • AMD Platform Management Framework (PMF)

Timeline

  • 2026-05-15: disclosed: Initial public disclosure by AMD and NVD.

References

Related threats