CVE-2025-0032 Details
Description
Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.
A vulnerability exists in the microcode patch loading process of AMD EPYC and Ryzen Embedded processors. This issue, caused by improper cleanup after loading CPU microcode patches, could enable an attacker with local administrator privileges to inject malicious microcode. The exploitation of this vulnerability may lead to a loss of integrity in x86 instruction execution.
Users are advised to update to the latest Platform Initialization (PI) firmware version. Specific update instructions can be obtained from the original equipment manufacturer (OEM).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 6, 2025CISA-ADP
Assessed Sep 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3014.html | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4012.html | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5007.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-459 | Incomplete Cleanup | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AMD EPYC 9005 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 9005 | All versions |
CPE
Remediation
| |
| AMD EPYC 9004 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 9004 | All versions |
CPE
Remediation
| |
| AMD EPYC 8004 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 8004 | All versions |
CPE
Remediation
| |
| AMD EPYC 7003 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 7003 | All versions |
CPE
Remediation
| |
| AMD EPYC 7002 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 7002 | All versions |
CPE
Remediation
| |
| AMD EPYC 4004 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 4004 | All versions |
CPE
Remediation
| |
| AMD Ryzen 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 6000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 6000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 5000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 5000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 4000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 4000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 2000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 2000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper PRO 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper PRO 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper PRO 5000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 6, 2025 | New CVE Received | [email protected] |
Volerion