AMD Processors Trusted Execution Environment Vulnerability Allowing Memory Overlap and Integrity Loss

Vulnerability

A vulnerability exists in the Trusted Execution Environment (TEE) of AMD processors, including certain Ryzen and Athlon mobile and desktop series, as well as embedded processors. This vulnerability stems from a failure to properly validate addresses and sizes, which could enable a malicious x86 attacker to send malformed messages to the graphics mailbox. Such actions may cause an overlap of a Trusted Memory Region (TMR) previously allocated by the ASP bootloader, potentially leading to unauthorized memory access and a loss of integrity.

Impact

Exploitation of this vulnerability could result in an overlap of a Trusted Memory Region (TMR) that was previously allocated by the ASP bootloader, leading to a potential loss of integrity.

Remediation

Users are advised to update to the latest Platform Initialization (PI) firmware version or AMD Software version available for their specific processor. For AMD Radeon graphics drivers, refer to the AMD Radeon Graphics Cards tables for the appropriate version.

Added: Sep 6, 2025, 8:19 PM
Updated: Sep 6, 2025, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.8
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.