« Back to list

AMD

AMD Platform Management Framework: vulnerabilities and CVEs

AMD Platform Management Framework has 9 published vulnerabilities, 9 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months9
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-48513Medium (6.9)0.10%—May 15, 2026
Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability.
CVE-2025-29938High (7.1)0.11%—May 15, 2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.
CVE-2025-29937Medium (5.8)0.10%—May 15, 2026
An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality.
CVE-2025-29936High (8.4)0.10%—May 15, 2026
Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation…
CVE-2025-29935High (8.4)0.11%—May 15, 2026
An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or…
CVE-2025-0028High (8.3)0.10%—May 15, 2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability.
CVE-2025-52540High (8.5)0.10%—May 15, 2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.
CVE-2025-48520Medium (6.9)0.10%—May 15, 2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash
CVE-2025-48519High (8.5)0.10%—May 15, 2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation6
  2. T1059 Command and Scripting Interpreter3
  3. T1005 Data from Local System1
  4. T1565 Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by AMD