Junglewise Threat Intelligence

CVE-2025-48512: AMD GPIO Driver privilege escalation via incorrect directory permissions

CVE-2025-48512 · Severity: info · CVSS 7 · Published 2026-05-15

Vendors: Amd.

Executive brief

A vulnerability in the installation directory of the AMD GPIO driver could allow a local user to gain elevated system privileges. The GPIO controller is a hardware component that manages communication between the processor and various peripheral devices. If exploited, an attacker could execute unauthorized commands with high-level permissions, potentially compromising the entire system.

Technical details

This vulnerability is classified as an incorrect default permission issue (CWE-276) within the installation directory of the AMD GPIO driver. Because the directory permissions are overly permissive, a local attacker with low privileges can modify or replace files used by the driver or associated services. An exploit requires local access and some level of user interaction to trigger the execution of the malicious files. Successful exploitation allows the attacker to escalate their privileges to a higher level, enabling arbitrary code execution in the context of the system.

Affected products

  • AMD GPIO Driver

Timeline

  • 2026-05-15: disclosed: Initial NVD publication date

References