CVE-2025-48510

7.1

AMD · uProf

A vulnerability in AMD uProf allows local attackers to bypass Kernel Address Space Layout Randomization (KSLR), leading to potential information disclosure or system availability loss.

Executive summary

A vulnerability in the AMD uProf driver allows a local, authenticated attacker to bypass critical security protections, necessitating an immediate update to version 5.0 or later.

Vulnerability

This flaw stems from an improper return value within the uProf utility (CWE-394). An attacker with local access and low privileges can leverage this issue to bypass KSLR, which is a security feature intended to prevent memory corruption exploits.

Business impact

The ability to bypass KSLR significantly lowers the barrier for attackers to develop reliable exploits for other vulnerabilities on the system. Successful exploitation could lead to unauthorized access to sensitive memory, resulting in a loss of confidentiality or system crashes that impact business operations. Given the CVSS score of 7.1, this is classified as a High severity risk that requires prompt attention to maintain a secure environment.

Remediation

Immediate Action: Update the AMD uProf software to version 5.0 or later as specified in the official AMD security bulletin (AMD-SB-9019).

Proactive Monitoring: Audit system logs for unusual local process activity or unauthorized attempts to access kernel-level debugging tools.

Compensating Controls: Restrict local access to systems running AMD uProf to only authorized personnel to reduce the surface area for local privilege escalation attacks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

While this vulnerability requires local access, it represents a significant security weakness in the underlying kernel protection mechanisms. IT administrators should prioritize patching the uProf utility across all affected environments to restore KSLR integrity and prevent potential secondary exploitation attempts.

More AMD CVEs

Sources

Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.