CVE-2025-48510CWE-394

Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability

High · published November 24, 2025

CVSS v3.1
7.1
EPSS
0%
Percentile
2.5
In the wild
Unconfirmed
What it is

⚡ A sneaky return value in AMD uProf could let local attackers dance past KSLR—imagine a VIP pass to your data party without the bouncer noticing! 🎉 Think of KSLR as a security guard who randomly rearranges the furniture at a venue to keep unwanted guests confused. If an attacker knows how the furniture is arranged, they can stroll right in, knowing exactly where the valuables are hidden. This vulnerability could lead to devastating consequences, such as unauthorized access to sensitive data or even service disruptions. With KSLR bypassed, an attacker could manipulate memory addresses, potentially wreaking havoc on the system's confidentiality and availability.

Put simply

Think of KSLR as a security guard who randomly rearranges the furniture at a venue to keep unwanted guests confused. If an attacker knows how the furniture is arranged, they can stroll right in, knowing exactly where the valuables are hidden. CVE-2025-48510 involves an improper return value in AMD uProf, allowing local attackers to bypass Kernel Address Space Layout Randomization (KSLR), which is designed to protect the system's memory layout from malicious actors.

What to do

This vulnerability could lead to devastating consequences, such as unauthorized access to sensitive data or even service disruptions. With KSLR bypassed, an attacker could manipulate memory addresses, potentially wreaking havoc on the system's confidentiality and availability. To remediate this, ensure you update to the latest firmware and patch released by AMD. Regularly audit your systems for compliance with security best practices and limit local user privileges where possible to reduce risk. You've got this! Follow the steps to secure your systems and keep those data party crashers out! 🛡️

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00125 · 2.5th percentile
Weakness
CWE-394 · Unexpected Status Code or Return Value
Published
2025-11-24T20:56Z
EPSS history
Timeline
  • 24 NOV 20:56Z
    Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability
    cvelistv5