CVE-2025-54502Disclosure

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668CWE-648

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-15); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 104-1404-1504-1604-17
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-152
Disclosure2
2026-04-161
General1
2026-04-171
Disclosure1
Full discourse5 posts
  • SKVLLZ.@xsh3llsh0ck
    Disclosure

    AMD has published Security Bulletin AMD-SB-7054 with my vulnerability CVE-2025-54502. There has been no feedback on my research (as well as my mention), so I will publish my work as it is and as soon as possible.

    Post summary

    The author indicates a new AMD vulnerability (CVE-2025-54502) that has been acknowledged in an AMD security bulletin, with plans to release detailed research soon, but no technical or exploit details are provided.

    37054177.1K
    81 followersView on X
  • PT SWARM@ptswarm
    Disclosure

    🔥 Read the new article by our researcher Timofey Duditsky. The write-up dives into the AMD Platform Configuration Blobs mechanism, shows how it works, and reveals the vulnerability CVE-2025-54502. https://swarm.ptsecurity.com/slowburn-looking-through-amd-platform-configuration-blobs-infrastructure/ https://t.co/bJzYSDZfn8

    Post summary

    The tweet announces a new vulnerability (CVE-2025-54502) discovered in AMD Platform Configuration Blobs, pointing to a research article that explains the mechanism, but provides no PoC, exploit, or mitigation information.

    01213083.7K
    18.8K followersView on X
  • SKVLLZ.@xsh3llsh0ck
    Disclosure

    The research has been published. In it, I describe the structure of APCB, show the functionality of the SMM driver that responds to it, and show where the CVE-2025-54502 vulnerability was. https://swarm.ptsecurity.com/slowburn-looking-through-amd-platform-configuration-blobs-infrastructure/

    Post summary

    The posted research outlines the APCB structure and SMM driver associated with CVE‑2025‑54502, marking its precise location but offering no exploit code, patch guidance, or evidence of active attacks.

    1721894.2K
    81 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-54502 Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privile… https://www.cve.org/CVERecord?id=CVE-2025-54502

    Post summary

    The post provides a brief disclosure of CVE‑2025‑54502, outlining a privilege‑escalation flaw in the AMD APCB SMM driver, but offers no PoC, exploit, active exploitation evidence, patch, or debunking claim.

    00010231
    57.2K followersView on X
  • SKVLLZ.@xsh3llsh0ck
    General

    There were some issues with publishing the CVE, but about an hour ago everything was fixed and it's now available: https://www.cve.org/CVERecord?id=CVE-2025-54502 I think I'm done with this.

    Post summary

    The user reports that the CVE record for CVE-2025-54502 has been made available after previous publishing issues.

    0000083
    73 followersView on X

Explore more