CVE-2025-29935
Summary
| CVE | CVE-2025-29935 |
|---|---|
| State | PUBLISHED |
| Assigner | AMD |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-15 03:16:21 UTC |
| Updated | 2026-05-15 03:16:21 UTC |
| Description | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability. |
Risk And Classification
Primary CVSS: v4.0 8.4 HIGH from [email protected]
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-787 | CWE-787 CWE-787 Out-of-bounds Write
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.4 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 8.4 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
NoneIntegrity
HighAvailability
HighSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | AMD | AMD Ryzen 7035 Series Processors With Radeon Graphics Formerly Codenamed Rembrandt R | unaffected 7.06.02.123 | Not specified |
| CNA | AMD | AMD Ryzen 7040 Series Mobile Processors With Radeon Graphics Formerly Codenamed Phoenix | unaffected 7.06.02.123 | Not specified |
| CNA | AMD | AMD Ryzen 8040 Series Mobile Processors With Radeon Graphics Formerly Codenamed Hawk Point | unaffected 7.06.02.123 | Not specified |
| CNA | AMD | AMD Ryzen 6000 Series Processors With Radeon Graphics Formerly Codenamed Rembrandt | unaffected 7.06.02.123 | Not specified |
| CNA | AMD | AMD Ryzen Embedded R8000 Series Processors | unaffected AMD Ryzen™ Chipset Driver 7.06.02.123 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.amd.com/en/resources/product-security/bulletin/AMD-SB-4015.html | [email protected] | www.amd.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Reported through AMD Bug Bounty Program (en)
There are currently no legacy QID mappings associated with this CVE.