CVE-2025-54502
Privilege Escalation via Boot Service Misuse in AMD APCB SMM Driver
Publication date: 2026-04-16
Last updated on: 2026-04-16
Assigner: Advanced Micro Devices Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | platform_configuration_blob | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-668 | The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the incorrect use of a boot service in the AMD Platform Configuration Blob (APCB) System Management Mode (SMM) driver. It could allow a privileged attacker who already has local access with Ring 0 privileges to escalate their privileges further, potentially enabling them to execute arbitrary code.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker with existing high-level local access to gain even greater privileges on the affected system. This privilege escalation could lead to arbitrary code execution, which might compromise system integrity, confidentiality, and availability.