CVE-2025-0032

HIGH

AMD CPU microcode - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.

Scores

CVSS v3 7.2
EPSS 0.0001
EPSS Percentile 1.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-459
Status published
Products (7)
AMD/AMD EPYC™ 9005 Series Processors TurinPI 1.0.0.4
AMD/AMD EPYC™ Embedded 9000 Series Processors Embturin PI 1.0.0.0
AMD/AMD Ryzen™ 9000 Series Desktop Processors ComboAM5PI 1.2.0.3c
AMD/AMD Ryzen™ 9000HX Series Processors FireRangeFL1PI 1.0.0.0a
AMD/AMD Ryzen™ AI 300 Series Processors StrixKrackanPI-FP8_1.1.0.1b
AMD/AMD Ryzen™ Al Max+ StrixHaloPI-FP11_1.0.0.1
AMD/AMD Ryzen™ Threadripper™ 9000 series ShimadaPeakPI-SP6 1.0.0.1
Published Sep 06, 2025
Tracked Since Feb 18, 2026