AMD AmdCpmDisplayFeatureSMM Driver SMM Callout Vulnerability Allowing SMRAM Overwrite and Potential Arbitrary Code Execution

Vulnerability

A vulnerability has been identified in the AmdCpmDisplayFeatureSMM driver, related to SMM callouts. This issue could enable locally authenticated attackers to overwrite SMRAM, which may lead to arbitrary code execution.

Impact

Exploitation of this vulnerability could allow for arbitrary code execution by overwriting SMRAM.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.