Junglewise Threat Intelligence

CVE-2025-29936: AMD Platform Management Framework improper input validation

CVE-2025-29936 · Severity: info · CVSS 8.4 · Published 2026-05-15

Technologies: Amd Platform Management Framework. Vendors: Amd.

Executive brief

A security vulnerability exists in the AMD Platform Management Framework, a system component responsible for managing power, performance, and thermal settings on AMD-based computers. An attacker with local access to the system could exploit this flaw to interfere with protected memory, potentially leading to a complete system takeover or the theft of sensitive information. This could allow a low-privileged user to gain administrative control over the affected device.

Technical details

The vulnerability is classified as improper input validation (CWE-20) within the AMD Platform Management Framework (PMF). A local attacker with low privileges can provide crafted input that causes the framework to unmap arbitrary memory pages. This memory manipulation can be leveraged to bypass security boundaries, potentially leading to local privilege escalation (LPE) or a denial-of-service (DoS) condition. The CVSS 4.0 score of 8.4 reflects high impact on integrity and availability across both the local and subsequent systems. Users are advised to refer to AMD security bulletin AMD-SB-4015 for specific firmware update versions.

Affected products

  • AMD Platform Management Framework (PMF)

Timeline

  • 2026-05-15: disclosed: Initial public disclosure via NVD and AMD advisory.

References

Related threats