AMD EPYC and Ryzen Processors System Management Mode Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability has been identified in AMD EPYC and Ryzen processors, specifically within the System Management Mode (SMM). This vulnerability arises from improper input validation, which could enable a privileged attacker to overwrite stack memory. Such an action may lead to arbitrary code execution. Affected products include various AMD EPYC processor series and AMD Ryzen processors, with specific firmware updates available to address this vulnerability.

Impact

Exploitation of this vulnerability could result in unauthorized stack memory modification, potentially allowing for arbitrary code execution on the affected system.

Remediation

Users are advised to update to the latest Platform Initialization (PI) or Secure Encrypted Virtualization (SEV) firmware version. Specific update details can be found in the AMD Security Bulletin AMD-SB-3023 for EPYC processors and AMD-SB-4013 for Ryzen processors.

Added: Feb 11, 2026, 2:46 AM
Updated: Feb 11, 2026, 2:46 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
2.2
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.