AMD Processors System Management Mode Vulnerability Allowing Execution of Attacker-Controlled Code

Vulnerability

A vulnerability exists in various AMD processors, including EPYC, Ryzen, and Athlon series, where a System Management Mode (SMM) handler may call code from non-SMM or untrusted memory. This flaw could enable a highly privileged attacker, with active user interaction and under specific complex conditions, to execute attacker-controlled code in SMM. Such an action could potentially compromise the system's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code in System Management Mode, allowing a highly privileged attacker to manipulate system processes and potentially compromise the overall security and stability of the system.

Remediation

Users are advised to update to the latest Platform Initialization (PI) firmware version available for their specific processor series. For AMD EPYC processors, the relevant PI versions have been released to Original Equipment Manufacturers (OEMs). Please contact the OEM for the appropriate BIOS update. For AMD Ryzen processors, similar guidance applies, with specific update versions listed in the official AMD security bulletin.

Added: May 15, 2026, 2:22 AM
Updated: May 15, 2026, 2:22 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
0.4
remediation
7.7
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.