Executive brief
A security vulnerability exists in the firmware of various AMD processors, specifically within a component that handles system configuration during the boot process. A highly privileged attacker with local access to the system could exploit this flaw to gain even deeper control over the hardware, potentially bypassing security protections. This could lead to the execution of unauthorized code at the highest level of system privilege, compromising the entire device's integrity.
Technical details
A vulnerability exists in the AMD Platform Configuration Blob (APCB) System Management Mode (SMM) driver due to the incorrect use of UEFI boot services. An attacker who has already obtained Ring 0 (kernel-level) privileges on a local system can exploit this flaw to escalate privileges to SMM, which operates with higher authority than the operating system kernel. This is classified as an incorrect use of privileged APIs (CWE-648) or exposure of resource to wrong sphere (CWE-668). Successful exploitation allows for arbitrary code execution within SMM, potentially leading to persistent firmware-level implants. AMD has released updated AGESA versions (e.g., GenoaPI_1.0.0.H, MilanPI-SP3_1.0.0.J) to mitigate this issue.
Affected products
- AMD EPYC 9004 Series Processors
- AMD EPYC 7003 Series Processors
- AMD EPYC 7002 Series Processors
- AMD EPYC 4004 Series Processors
- AMD EPYC 9005 Series Processors
- AMD Instinct MI300A Series Processors
- AMD Ryzen 4000 Series Mobile Processors
- AMD Ryzen 7035 Series Processors
Timeline
- 2025-01-01: disclosed: Initial internal tracking date
- 2026-04-16: advisory: Public disclosure of CVE-2025-54502