Executive brief
A security vulnerability has been identified in the AMD Platform Management Framework (PMF), a component responsible for managing power and performance on AMD-based systems. An attacker with local access to a system could exploit this flaw to read sensitive information from the computer's memory or cause the system to crash. This could lead to the exposure of confidential data or a disruption of business operations due to system instability.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists within the AMD Platform Management Framework (PMF). The flaw is triggered when the component fails to properly validate memory boundaries during read operations. A local attacker with low privileges can exploit this to read arbitrary memory locations. Successful exploitation can result in the disclosure of sensitive information (loss of confidentiality) or a system crash (loss of availability). The attack requires local access and is categorized with a CVSS 4.0 base score of 5.8.
Affected products
- AMD Platform Management Framework (PMF)
Timeline
- 2026-05-15: advisory: NVD publication date