Description
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.
Published: 2026-05-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unchecked return value within AMD’s Platform Management Framework, a flaw identified as CWE-252, permits an attacker to write to an arbitrary memory address, which can lead to denial of service or arbitrary code execution. The flaw arises when the framework ignores the success status of a low‑level memory operation, enabling the attacker to control the destination pointer. This effect directly threatens the integrity and availability of the system, as memory corruption can disrupt normal operation or allow execution of malicious code.

Affected Systems

This vulnerability affects AMD Ryzen Embedded 8000 Series, Ryzen 7035 Series with Radeon Graphics (formerly Rembrandt R), Ryzen 7040 Series Mobile with Radeon Graphics (formerly Phoenix), and Ryzen 8040 Series Mobile with Radeon Graphics (formerly Hawk Point). The advisory does not list specific firmware versions; any system running the AMD Platform Management Framework on these processors is potentially vulnerable.

Risk and Exploitability

The CVSS score is 7.1, indicating a high impact level. No EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly observed exploitation yet. Based on the description, a local or privileged attacker with access to the system’s firmware could exploit the flaw by invoking the affected PMF API; this inference is made from the nature of the memory write attack. A remote vector would require the ability to trigger the API from an external interface, which is not detailed in the advisory and is thus inferred as a possibility.

Generated by OpenCVE AI on May 15, 2026 at 06:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest BIOS or firmware update from AMD that addresses the Platform Management Framework issue.
  • If no update is available, disable or restrict external access to the Platform Management Framework interface to limit privileged use.
  • If the platform supports isolation, restrict untrusted code from invoking the PMF API to mitigate the unchecked return value issue.

Generated by OpenCVE AI on May 15, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 15 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd ryzen 7035 Series Processors With Radeon Graphics
Amd ryzen 7040 Series Mobile Processors With Radeon Graphics
Amd ryzen 8040 Series Mobile Processors With Radeon Graphics
Amd ryzen Embedded 8000 Series Processors
Vendors & Products Amd
Amd ryzen 7035 Series Processors With Radeon Graphics
Amd ryzen 7040 Series Mobile Processors With Radeon Graphics
Amd ryzen 8040 Series Mobile Processors With Radeon Graphics
Amd ryzen Embedded 8000 Series Processors

Fri, 15 May 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unchecked return value in AMD PMF enables arbitrary memory write

Fri, 15 May 2026 03:00:00 +0000

Type Values Removed Values Added
Description An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.
Weaknesses CWE-252
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Amd Ryzen 7035 Series Processors With Radeon Graphics Ryzen 7040 Series Mobile Processors With Radeon Graphics Ryzen 8040 Series Mobile Processors With Radeon Graphics Ryzen Embedded 8000 Series Processors
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-05-16T03:55:57.671Z

Reserved: 2025-03-12T15:14:59.391Z

Link: CVE-2025-29938

cve-icon Vulnrichment

Updated: 2026-05-15T13:29:05.577Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-15T03:16:21.813

Modified: 2026-05-15T14:10:17.083

Link: CVE-2025-29938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T11:21:00Z

Weaknesses