Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2024-21962HIGHImproper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in pEPSS 0.1%CVE-2025-54514MEDIUMImproper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a EPSS 0.1%CVE-2024-36332MEDIUMImproper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to perform unauthorizeEPSS 0.1%CVE-2026-0432HIGHIncorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalatiEPSS 0.1%CVE-2025-48513MEDIUMUse of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memoEPSS 0.1%CVE-2023-31324HIGHA Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global MemoEPSS 0.1%CVE-2023-31317HIGHImproper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read orEPSS 0.1%CVE-2023-20548HIGHA Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting inEPSS 0.1%CVE-2025-29937MEDIUMAn out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory loEPSS 0.1%CVE-2025-29936HIGHImproper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentiEPSS 0.1%CVE-2025-0028HIGHAn unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary addressEPSS 0.1%CVE-2025-61970HIGHWeak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary codEPSS 0.1%CVE-2023-31313HIGHAn unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messagesEPSS 0.1%CVE-2024-36347MEDIUMImproper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicEPSS 0.1%CVE-2021-26380LOWA compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside the intended range reEPSS 0.1%CVE-2023-20570LOWInsufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bEPSS 0.1%CVE-2025-48521MEDIUMImproper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) conditEPSS 0.1%CVE-2025-29944MEDIUMA buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resultingEPSS 0.1%CVE-2025-66660LOWInsufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cEPSS 0.1%CVE-2026-0428LOWInsufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGSEPSS 0.1%