Home

Description

Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.

PUBLISHED Reserved 2025-05-22 | Published 2026-05-15 | Updated 2026-05-16 | Assigner AMD




HIGH: 7.0CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-276 Incorrect Default Permissions

Product status

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

7.04.09.545
unaffected

Default status
affected

25Q3 AMD Emb [R1000 V1000] Win® Chipset WHQL certified driver - (71252)
unaffected

Default status
affected

Q2 - 2025 AMD Embedded R2000, V2000 Windows® Chipset drivers (68915)
unaffected

Default status
affected

25Q3 AMD Emb [R1000 V1000] Win® Chipset WHQL certified driver - (71252)
unaffected

Default status
affected

Q2 - 2025 AMD Embedded R2000, V2000 Windows® Chipset drivers (68915)
unaffected

Default status
affected

Q4 - 2025 AMD Embedded Windows® Chipset drivers (71816)
unaffected

Default status
affected

Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Chipset drivers [7.06.02.123] (68927)
unaffected

Default status
affected

Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Chipset drivers [7.06.02.123] (68927)
unaffected

Default status
affected

Q4 - 2025 AMD Embedded Windows® Chipset drivers (71816)
unaffected

Default status
affected

Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Chipset drivers [7.06.02.123] (68927)
unaffected

Default status
affected

AMD Server Software 8.03.16.641
unaffected

Default status
affected

AMD Server Software 8.03.14.329
unaffected

Default status
affected

AMD Server Software 8.03.14.329
unaffected

Default status
affected

AMD Server Software 8.03.14.329
unaffected

Default status
affected

AMD Chipset Driver 7.04.09.545
unaffected

Default status
affected

AMD Server Software 8.03.16.641
unaffected

Default status
affected

AMD Server Software 8.03.16.641
unaffected

Default status
affected

AMD Server Software 8.03.16.641
unaffected

Default status
affected

AMD Server Software 8.03.16.641
unaffected

Default status
affected

AMD Chipset Driver 7.04.09.545
unaffected

Credits

Reported through AMD Bug Bounty Program

References

www.amd.com/...es/product-security/bulletin/AMD-SB-4015.html

www.amd.com/...es/product-security/bulletin/AMD-SB-3047.html

cve.org (CVE-2025-48512)

nvd.nist.gov (CVE-2025-48512)

Download JSON