Executive brief
A security vulnerability exists in the AMD driver responsible for managing system power and performance. A local user with limited privileges could exploit this flaw to access restricted system memory or cause the computer to crash. This could lead to the exposure of sensitive information or a disruption of business operations due to system instability.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the AMD Platform Management Framework (PMF) driver due to improper input validation. A local attacker with low privileges can provide crafted input to the driver to trigger a read beyond the intended memory buffer. This can result in the disclosure of sensitive kernel-space information or lead to a denial-of-service condition via a system crash. The vulnerability is tracked as CVE-2025-48520 and has been addressed in AMD security bulletin AMD-SB-4015.
Affected products
- AMD Platform Management Framework (PMF) Driver
Timeline
- 2026-05-15: disclosed: Initial publication of the CVE record and AMD advisory.