Executive brief
A security vulnerability exists in the AMD Platform Management Framework (PMF) driver, which is responsible for managing power, thermal, and performance settings on AMD-based computers. A local user with low-level access could exploit this flaw to gain higher administrative privileges on the system. This could allow an attacker to take full control of the affected device, potentially leading to unauthorized data access or system disruption.
Technical details
An improper input validation vulnerability exists within the AMD Platform Management Framework (PMF) driver, classified as an out-of-bounds write (CWE-787). The flaw resides in how the driver processes input, allowing a local attacker with low privileges to read or write to memory locations outside of the intended buffer. This memory corruption can be leveraged to achieve local privilege escalation (LPE). The attack requires local access but no user interaction. AMD has addressed this in security bulletin AMD-SB-4015.
Affected products
- AMD Platform Management Framework (PMF) Driver
Timeline
- 2026-05-15: disclosed: Initial public disclosure by AMD and NVD.