Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2025-29938HIGHAn unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory addressEPSS 0.1%CVE-2026-0465MEDIUMA Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentialEPSS 0.1%CVE-2025-29935HIGHAn out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated pEPSS 0.1%CVE-2025-48505HIGHWeak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged eEPSS 0.1%CVE-2021-26396MEDIUMInsufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. EPSS 0.1%CVE-2023-31309MEDIUMImproper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when expoEPSS 0.1%CVE-2025-66664MEDIUMInsufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_IDEPSS 0.1%CVE-2026-0427MEDIUMImproper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to EPSS 0.1%CVE-2025-0045MEDIUMImproper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potEPSS 0.1%CVE-2025-48502MEDIUMImproper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial oEPSS 0.1%CVE-2025-48511MEDIUMImproper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crEPSS 0.1%CVE-2025-29933MEDIUMImproper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of EPSS 0.1%CVE-2025-62628HIGHUnsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentialEPSS 0.1%CVE-2025-29934MEDIUMA bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resultiEPSS 0.1%CVE-2024-36345MEDIUMImproper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an outEPSS 0.1%CVE-2025-0007MEDIUMInsufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user space to kernel spaceEPSS 0.1%CVE-2025-54510MEDIUMA missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privilegeEPSS 0.1%CVE-2025-0046HIGHIncorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.EPSS 0.1%CVE-2025-62624HIGHA heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially EPSS 0.1%CVE-2025-48512HIGHIncorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attackEPSS 0.1%