Executive brief
A vulnerability in the AMD Platform Management Framework (PMF), which manages power and performance on AMD-based systems, could allow an attacker with local access to interfere with system memory. This could lead to a complete system crash or allow the attacker to run unauthorized code, potentially compromising the security and stability of the device. This issue primarily impacts the reliability of the hardware and the integrity of the operating environment.
Technical details
A vulnerability classified as CWE-252 (Unchecked Return Value) exists within the AMD Platform Management Framework (PMF). The flaw occurs when the software fails to validate the return value of a function, potentially leading to an arbitrary memory write. An attacker with local low-privileged access could exploit this condition to trigger a denial of service (system crash) or achieve arbitrary code execution. The attack requires local access and specific timing or environmental conditions (AT:P), but no user interaction is required. AMD has assigned a CVSS 4.0 score of 7.1.
Affected products
- AMD Platform Management Framework (PMF)
Timeline
- 2026-05-15: disclosed: Initial NVD publication date