# CVE-2025-0032

## Summary

- **CVE ID:** CVE-2025-0032
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N)
- **CWE:** CWE-459
- **Published:** Sep 6, 2025
- **Last Modified:** Mar 13, 2026

## Description

Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.

## Affected Products

- AMD — AMD EPYC™ 9005 Series Processors (TurinPI 1.0.0.4)
- AMD — AMD Ryzen™ AI 300 Series Processors (StrixKrackanPI-FP8_1.1.0.1b)
- AMD — AMD Ryzen™ 9000 Series Desktop Processors (ComboAM5PI 1.2.0.3c)
- AMD — AMD Ryzen™ 9000HX Series Processors (FireRangeFL1PI 1.0.0.0a)
- AMD — AMD Ryzen™ Al Max+ (StrixHaloPI-FP11_1.0.0.1)
- AMD — AMD Ryzen™ Threadripper™ 9000 series (ShimadaPeakPI-SP6 1.0.0.1)
- AMD — AMD EPYC™ Embedded 9000 Series Processors (Embturin PI 1.0.0.0)

## References

- [CNA](https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4012.html)
- [CNA](https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5007.html)
- [CNA](https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3014.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._