Junglewise Threat Intelligence

CVE-2025-48513: AMD Platform Management Framework use of uninitialized resource

CVE-2025-48513 · Severity: info · CVSS 6.9 · Published 2026-05-15

Technologies: Amd Platform Management Framework. Vendors: Amd.

Executive brief

A security vulnerability exists in the AMD Platform Management Framework, which is responsible for managing system power and performance on AMD-based computers. An attacker with local access to the system could exploit this flaw to view sensitive information stored in the computer's protected kernel memory. This could lead to the exposure of private data or cause system instability and crashes.

Technical details

A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists within the AMD Platform Management Framework (PMF). The flaw occurs when the framework fails to properly initialize memory resources before they are accessed or returned. A local attacker with low privileges can exploit this to leak sensitive information from kernel memory (loss of confidentiality) or potentially trigger a system crash (loss of availability). The attack requires local access but no user interaction. AMD has addressed this in security bulletin AMD-SB-4015.

Affected products

  • AMD Platform Management Framework (PMF)

Timeline

  • 2026-05-15: disclosed: Initial publication of the CVE record.

References

Related threats