Vulnerabilities in AMD

445 results
Vexday analysis

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2023-31365LOWAn integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resultEPSS 0.1%CVE-2024-21962HIGHImproper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in pEPSS 0.1%CVE-2025-48512HIGHIncorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attackEPSS 0.1%CVE-2024-36332MEDIUMImproper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to perform unauthorizeEPSS 0.1%CVE-2026-0432HIGHIncorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalatiEPSS 0.1%CVE-2025-48513MEDIUMUse of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memoEPSS 0.1%CVE-2025-29937MEDIUMAn out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory loEPSS 0.1%CVE-2025-0028HIGHAn unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary addressEPSS 0.1%CVE-2025-29936HIGHImproper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentiEPSS 0.1%CVE-2023-31317HIGHImproper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read orEPSS 0.1%CVE-2023-20570LOWInsufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bEPSS 0.1%CVE-2021-26380LOWA compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside the intended range reEPSS 0.1%CVE-2025-29944MEDIUMA buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resultingEPSS 0.1%CVE-2023-20548HIGHA Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting inEPSS 0.1%CVE-2023-31324HIGHA Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global MemoEPSS 0.1%CVE-2025-54514MEDIUMImproper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a EPSS 0.1%CVE-2026-0428LOWInsufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGSEPSS 0.1%CVE-2025-66660LOWInsufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cEPSS 0.1%CVE-2025-48521MEDIUMImproper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) conditEPSS 0.1%CVE-2026-0466MEDIUMImproper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentialEPSS 0.1%