Executive brief
A security vulnerability has been identified in the AMD Platform Management Framework (PMF) driver, which manages system performance and power settings on AMD-based computers. A local user with low-level access could exploit this flaw to gain higher-level administrative or system privileges. This could allow an attacker to take full control of the affected machine, potentially leading to data theft or persistent system compromise.
Technical details
An out-of-bounds (OOB) write vulnerability (CWE-787) exists in the AMD Platform Management Framework (PMF) Driver due to improper input validation. A local attacker with low privileges can provide crafted input to the driver to trigger a memory corruption event. Successful exploitation allows the attacker to overwrite sensitive kernel-mode memory, which can be leveraged to escalate privileges to SYSTEM or administrative levels. The vulnerability is reachable locally without user interaction. Users are advised to refer to AMD security bulletin AMD-SB-4015 for specific driver update versions.
Affected products
- AMD Platform Management Framework (PMF) Driver
Timeline
- 2026-05-15: disclosed: Initial NVD publication date