PatchSiren

AMD CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AMD CVE published 2026-09-02

CVE-2023-20577

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T20:17:34.093Z and has not been modified since then. This vulnerability, CVE-2023-20577, involves a heap overflow in the SMM module, which may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. The affected [truncated]

HIGH AMD CVE published 2026-09-02

CVE-2023-20576

Insufficient Verification of Data Authenticity in AGESA may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. This vulnerability affects products utilizing AGESA, emphasizing the need for verifying affected products and applying vendor remediation. The technical impact involves potential system compromise through SPI ROM data manipulation. Evidenc [truncated]

LOW AMD CVE published 2026-08-31

CVE-2023-31308

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T19:16:44.890Z and has not been modified since then. This vulnerability, CVE-2023-31308, involves a malicious virtual function that can invoke certain command handlers in the SMU, leading to a denial of service due to an out-of-bounds memory read. The vulnerability has a CVSS score of 3.3 and is c [truncated]

HIGH AMD CVE published 2026-08-11

CVE-2025-54512

A local user-privileged attacker could exploit a DLL hijacking vulnerability in the AMD Ryzen Master installation to escalate privileges, potentially allowing arbitrary code execution. Defenders should assess exposure, prioritize remediation, and verify affected versions and scope. The vulnerability's impact includes potential privilege escalation to arbitrary code execution, and defenders should verify a [truncated]

HIGH AMD CVE published 2026-08-11

CVE-2025-0046

CVE-2025-0046 is a high-severity vulnerability in AMD Power Design Manager (PDM) Software Installer for Windows, with a CVSS score of 7. The vulnerability is caused by incorrect directory permissions, which could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution. The CVE record was published on 2026-08-11T18:17:17.420Z and was last modified on 2026-09-29T11 [truncated]

HIGH AMD CVE published 2026-08-11

CVE-2025-8087

A DLL hijacking vulnerability exists in AMD Power Design Manager, allowing malicious local attackers to escalate privileges during uninstallation, potentially leading to arbitrary code execution. This vulnerability requires verification of exposure, especially in systems where AMD Power Design Manager is installed, and prioritization of mitigation efforts based on the CVSS score of 7 and HIGH severity cla [truncated]

LOW AMD CVE published 2026-08-11

CVE-2025-61970

A low-privileged user could create arbitrary code in the Vitis Unified installation path on local Windows machines, potentially resulting in binary hijacking. This vulnerability exists due to weak permissions in the Vitis Unified installation path, posing a risk to systems where low-privileged users have write access to the installation path. Defenders responsible for Vitis Embedded Single File Download ( [truncated]

MEDIUM AMD CVE published 2026-08-11

CVE-2025-48506

CVE-2025-48506 debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T17:17:44.200Z and has not been modified since then. This MEDIUM-severity vulnerability in Vitis Unified installations on local Windows machines could allow DLL injection, potentially resulting in arbitrary code execution. Defenders should assess exposure, verify installation paths, and update configurati [truncated]

LOW AMD CVE published 2026-08-11

CVE-2025-48505

A low-privileged user could potentially achieve privileged escalation on local Windows machines with weak permissions in the Vitis Unified installation path, which may result in arbitrary code execution. This vulnerability, identified as CVE-2025-48505, involves a weakness in the Vitis Unified installation path that could be exploited by a low-privileged user to elevate their privileges, potentially leadi [truncated]

MEDIUM AMD CVE published 2026-08-11

CVE-2025-0041

CVE-2025-0041: Uncontrolled search paths in Vitis Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution. AMD has released a bulletin (AMD-SB-8015) addressing this issue. The CVE record was published on 2026-08-11T17:17:42.140Z and was last modified on 2026-09-29T11:10:00.150Z. The NVD entry is currently Awaiting Analysis.

HIGH AMD CVE published 2026-06-12

CVE-2026-40677

CVE-2026-40677 is a HIGH-severity vulnerability (CVSS score: 7.7) that was published on 2026-06-12T16:16:27.400Z and modified on 2026-06-12T16:22:46.947Z. The vulnerability is related to the use of insecure HTTP transport within AMD optional tools, which could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution. The CVE record [resourceLinkAnnotations:c [truncated]

MEDIUM AMD CVE published 2026-06-10

CVE-2024-21944

CVE-2024-21944 is a medium-severity vulnerability (CVSS Score: 5.3) that involves improper input validation for DIMM serial presence detect (SPD) metadata. This vulnerability could potentially allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to overwrite guest memory, resulting in loss of guest data integrity.

MEDIUM AMD CVE published 2026-06-09

CVE-2026-28237

A vulnerability in AMD uProf, tracked as CVE-2026-28237, may allow for unrestricted resource allocation. This could be exploited to consume excessive system resources, potentially leading to a loss of availability. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity.

MEDIUM AMD CVE published 2026-06-09

CVE-2026-0466

CVE-2026-0466 is a MEDIUM-severity vulnerability in AMD uProf, a profiling tool for AMD processors. The vulnerability is caused by improper access control, allowing a local attacker with user privileges to write to the kernel-shared memory section. This could potentially result in a crash or denial of service.

MEDIUM AMD CVE published 2026-06-09

CVE-2025-54509

CVE-2025-54509 is a Medium severity vulnerability (CVSS Score: 4) affecting an unknown vendor and product. The vulnerability is related to improper access control for the register interface in the input-output memory management unit (IOMMU), which could allow a privileged attacker to cause non-coherent accesses by the AMD secure processor (ASP), potentially resulting in loss of integrity.

MEDIUM AMD CVE published 2026-05-19

CVE-2024-36343

CVE-2024-36343 is a medium-severity vulnerability (CVSS 4.6) affecting AMD products, published on 2026-05-19 and last modified on 2026-05-20. The vulnerability stems from improper input validation in the System Management Mode (SMM) communications buffer, which could allow a privileged attacker with local access and high privileges to perform out-of-bounds read or write operations to a limited section of [truncated]

HIGH AMD CVE published 2026-05-15

CVE-2025-54518

CVE-2025-54518 is a high-severity vulnerability affecting Zen 2-based products. The issue involves improper isolation of shared resources within the CPU operation cache, which could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.3, indicating a [truncated]

HIGH Amd CVE published 2026-05-15

CVE-2024-36333

CVE-2024-36333 is a high-severity DLL hijacking issue in AMD Cleanup Utility. According to the NVD record, a low-privilege local attacker with user interaction may be able to influence DLL loading and escalate privileges, potentially resulting in arbitrary code execution. NVD cites AMD’s security bulletin as the vendor remediation reference and lists AMD Cleanup Utility 25.20.00.00 among the affected products.

HIGH AMD CVE published 2026-05-13

CVE-2025-62627

An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability. This vulnerability affects ESXi environments, particularly those using AMD-Pensando DPU products. Defenders should assess exposure and potential impact, focusing on E [truncated]

HIGH AMD CVE published 2026-05-13

CVE-2025-62624

A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. This vulnerability affects VMware ESXi hosts using AMD-Pensando DPU products and requires immediate attention from administrators and security teams to assess exposure and prioritize patching. The CVE record and NVD entry provide [truncated]

HIGH AMD CVE published 2026-05-13

CVE-2025-62623

A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. This vulnerability affects VMware ESXi hosts using AMD-Pensando DPU products, requiring prompt attention from administrators and security teams to assess exposure and prioritize patching. The vulnerability has a CVSS score of 8.8 [truncated]

HIGH AMD CVE published 2026-04-16

CVE-2025-54502

CVE-2025-54502 is a HIGH-severity vulnerability in the AMD Platform Configuration Blob (APCB) SMM driver. A privileged attacker with local access (Ring 0) could exploit this vulnerability to achieve privilege escalation, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 7.1. The CVE was published on 2026-04-16 and last modified on 2026-06-30. AMD has released a securit [truncated]

MEDIUM AMD CVE published 2025-04-07

CVE-2023-20593

CVE-2023-20593 is a medium-severity information disclosure issue in certain AMD processors. In the ABB/CISA advisory, the exposure is tied to ABB M2M Gateway ARM600 firmware and software deployments, with an important caveat: the advisory says ARM600 servers use Intel processors, but some ARM600 SW installations may run in AMD processor environments. The main risk is confidentiality loss, not code executi [truncated]

MEDIUM AMD CVE published 2025-04-07

CVE-2023-20569

CVE-2023-20569 is a speculative-execution information disclosure issue affecting certain AMD processors. In ABB’s advisory for ARM600, the vendor notes that ARM600 servers use Intel processors, but ARM600 software installations may exist in AMD processor environments. The affected ABB products listed are ARM600 firmware versions 4.1.2 through 5.0.3 and ARM600 SW versions 5.0.1 through 5.0.3. The primary d [truncated]

MEDIUM AMD CVE published 2025-04-07

CVE-2021-26401

CISA’s 2025-04-07 advisory for ABB M2M Gateway (ARM600) ties CVE-2021-26401 to a flaw in certain AMD processors involving the LONGJMP assembly command. The issue is described as potentially enabling arbitrary code execution. ABB’s affected product ranges are ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. The advisory also notes that ARM600 servers include Intel processors, [truncated]