# CVE-2025-0028

## Summary

- **CVE ID:** CVE-2025-0028
- **Severity:** HIGH
- **CVSS Score:** 8.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H)
- **CWE:** CWE-252
- **Published:** May 15, 2026
- **Last Modified:** May 15, 2026

## Description

An unchecked return value within the AMD Platform Management Framework (PMF)  could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability.

## Affected Products

- AMD — AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R") (7.06.02.123)
- AMD — AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix") (7.06.02.123)
- AMD — AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Hawk Point") (7.06.02.123)
- AMD — AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt") (7.06.02.123)
- AMD — AMD Ryzen™ Embedded 8000 Series Processors (AMD Ryzen™ Chipset Driver 7.06.02.123)

## References

- [CNA](https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4015.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._