AMD Secure Processor Access Control Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability in the AMD Secure Processor (ASP) has been identified, stemming from insufficient granularity of access control. This flaw may enable an attacker with an untrusted user space application to map sensitive System Management Network (SMN) apertures, potentially leading to unauthorized privilege escalation. The issue affects several AMD Ryzen and Ryzen Embedded series processors.

Impact

Exploitation of this vulnerability could allow an attacker to escalate privileges on the affected system.

Remediation

Users are advised to update to the Platform Initialization (PI) firmware version 1.2.0.8 for AMD Ryzen 3000 Series Desktop Processors, AMD Ryzen 4000 Series Desktop Processors, AMD Ryzen 5000 Series Desktop Processors, and AMD Ryzen 5000 Series Mobile Processors with Radeon Graphics. For AMD Ryzen Embedded V1000 Series Processors, the recommended update is to version 1.0.0.2. Please contact your OEM for the BIOS update specific to your product.

Added: Jun 1, 2026, 9:39 PM
Updated: Jun 1, 2026, 9:39 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
5.0
exploitability
3.3
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.