AMD EPYC and Ryzen Embedded Processors CPU Microcode Loading Vulnerability Allowing Integrity Loss in Instruction Execution

Vulnerability

A vulnerability exists in the microcode patch loading process of AMD EPYC and Ryzen Embedded processors. This issue, caused by improper cleanup after loading CPU microcode patches, could enable an attacker with local administrator privileges to inject malicious microcode. The exploitation of this vulnerability may lead to a loss of integrity in x86 instruction execution.

Impact

Exploitation of this vulnerability could result in a compromised integrity of x86 instruction execution, allowing for potentially malicious actions to be carried out at the instruction level.

Remediation

Users are advised to update to the latest Platform Initialization (PI) firmware version. Specific update instructions can be obtained from the original equipment manufacturer (OEM).

Added: Sep 7, 2025, 1:45 AM
Updated: Sep 7, 2025, 1:45 AM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
2.8
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.