Incorrect use of LocateProtocol Service of the EFI_BOOT_Services table in SMI Handler

Summary

Incorrect use of LocateProtocol Service by a privileged attacker with local access could potentially result in privilege escalation from Ring 0 to System Management Mode (SMM) potentially resulting in Arbitrary Code Execution.

CVE Details

Refer to Glossary for explanation of terms

CVE

CVE Description

CVSS Score

CVE-2025-54502

Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.

7.1 (High)

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products and Mitigation 

AMD recommends updating to the Platform Initialization (PI) versions indicated below.

Note: Mitigations were, or will be, released by AMD to the Original Equipment Manufacturers (OEM) on the dates listed below. Please contact your OEM for the BIOS update specific to your product(s).

*Note: Products believed to not be affected by the listed CVE(s) are not included.  

AMD EPYC™ Processors
Product Mitigation Release Date
AMD EPYC™ 4004 Series Processors ComboAM5PI 1.0.0.d 2025-11-12
AMD EPYC™ 7002 Series Processors RomePI 1.0.0.P 2025-11-04
2025-12-02AMD EPYC™ 7003 Series Processors MilanPI 1.0.0.J 2025-12-15
AMD EPYC™ 8004 Series Processors GenoaPI 1.0.0.H 2025-12-15
AMD EPYC™ 9004 Series Processors GenoaPI 1.0.0.H 2025-12-15
AMD EPYC™ 9004 Series Processors GenoaPI 1.0.0.H 2025-12-15
AMD EPYC™ 9005 Series Processors TurinPI 1.0.0.9 2025-12-31
AMD EPYC™ 9V64H Processor MI300C 1.0.0.3 2025-12-10
AMD Instinct™ MI300A Series Processors MI300A 1.0.0.C 2025-12-11
AMD Ryzen™ Processors
Product Mitigation Release Date
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics PicassoPI-FP5_1.0.1.2e 2025-11-19
AMD Ryzen™ 3000 Series Desktop Processors ComboAM4v2PI 1.2.0.10 2025-10-31
ComboAM4PI 1.0.0.10 2025-10-24
AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics PicassoPI-FP5_1.0.1.2e 2025-11-19
AMD Ryzen™ 4000 Series Desktop Processors ComboAM4v2PI 1.2.0.10 2025-10-31
AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics RenoirPI-FP6 1.0.0.Ed 2025-11-11
AMD Ryzen™ 5000 Series Desktop Processors ComboAM4v2PI 1.2.0.10 2025-10-31
AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics ComboAM4v2PI 1.2.0.10 2025-10-31
AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics CezannePI-FP6_1.0.1.1d 2025-12-02
AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics RembrandtPI-FP7_1.0.0.Bg 2025-12-09
AMD Ryzen™ 7000 Series Desktop Processors ComboAM5PI 1.0.0.d 2025-11-12
ComboAM5PI 1.1.0.3f 2025-11-16
ComboAM5PI 1.2.0.3h 2025-10-22
ComboAM5PI 1.2.8.0 2025-11-21
AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics MendocinoPI-FT6_1.0.0.7g 2025-11-11
AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics CezannePI-FP6_1.0.1.1d 2025-12-02
AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics RembrandtPI-FP7_1.0.0.Bg 2025-12-09
AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics PhoenixPI-FP8-FP7_1.2.0.0f 2026-01-31
AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics DragonRangeFL1PI 1.0.0.3k 2025-12-04
AMD Ryzen™ 8000 Series Desktop Processors ComboAM5PI 1.1.0.3f 2025-11-16
ComboAM5PI 1.2.0.3h 2025-10-22
ComboAM5PI 1.2.8.0 2025-11-21
AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics PhoenixPI-FP8-FP7_1.2.0.0f 2026-01-31
AMD Ryzen™ 9000 Series Desktop Processors ComboAM5PI 1.2.0.3h 2025-10-22
ComboAM5PI 1.2.8.0 2025-11-21
AMD Ryzen™ 9000HX Series Processors FireRangeFL1PI 1.0.0.0d 2025-10-26
AMD Ryzen™ AI 300 Series Processors StrixKrackanPI-FP8_1.1.0.0e 2025-12-17
AMD Ryzen™ AI Max 300 Series Processors StrixHaloPI-FP11_1.0.0.2a 2025-11-25
AMD Ryzen™ Threadripper™ 7000 Processors ShimadaPeakPI-SP6 1.0.0.1c 2025-10-21
AMD Ryzen™ Threadripper™ 9000 Processors ShimadaPeakPI-SP6 1.0.0.1c 2025-10-21
AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors ChagallWSPI-sWRX8 1.0.0.D 2025-11-04
CastlePeakWSPI-sWRX8 1.0.0.I 2025-10-17
AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors ChagallWSPI-sWRX8 1.0.0.D 2025-11-04
AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors ShimadaPeakPI-SP6 1.0.0.1c 2025-10-21
StormPeakPI-SP6 1.0.0.1m 2025-12-01
StormPeakPI-SP6_1.1.0.0k 2025-12-01
AMD Ryzen™ Threadripper™ PRO 9000 WX-Series Processors ShimadaPeakPI-SP6 1.0.0.1c 2025-10-21
AMD Ryzen™ Z1 Series Processors PhoenixPI-FP8-FP7_1.2.0.0f 2026-01-31
AMD Ryzen™ Z2 Series Processors Extreme StrixKrackanPI-FP8_1102d 2025-12-10
AMD Ryzen™ AI Z2 Extreme StrixKrackanPI-FP8_1102d 2025-12-10
AMD Ryzen™ Z2 Series Processors PhoenixPI-FP8-FP7_1.2.0.0f 2026-01-31
AMD Ryzen™ Z2 Series Processors Go RembrandtPI-FP7_1.0.0.Bg 2025-12-09
AMD EPYC™ and Ryzen™ Embedded Processors
Product Mitigation Release Date
AMD EPYC™ Embedded 7002 Series Processors EmbRomePI-SP3 1.0.0.F 2025-12-10
AMD EPYC™ Embedded 7003 Series Processors EmbMilanPI-SP3 1.0.0.D 2026-01-02
AMD EPYC™ Embedded 8004 Series Processors EmbGenoaPI-SP5 1.0.0.D 2026-02-02
AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo") EmbGenoaPI-SP5 1.0.0.D 2026-02-02
AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa") EmbGenoaPI-SP5 1.0.0.D 2026-02-02
AMD EPYC™ Embedded 9005 Series Processors Version TBD Target release April 2026
AMD Ryzen™ Embedded 5000 Series Processors EmbAM4PI 1.0.0.9 2026-01-31
AMD Ryzen™ Embedded 7000 Series Processors EmbeddedAM5PI 1.0.0.7 2026-03-31
AMD Ryzen™ Embedded 8000 Series Processors EmbeddedPhoenixPI-FP7r2_1.0.0.4 2026-03-31
AMD Ryzen™ Embedded 9000 Series Processors EmbeddedAM5PI 1.0.0.5 2025-12-26
AMD Ryzen™ Embedded R1000 Series Processors EmbeddedPI-FP5 1213 2026-03-31
AMD Ryzen™ Embedded R2000 Series Processors EmbeddedR2KPI-FP5 1008 2026-03-31
AMD Ryzen™ Embedded V1000 Series Processors (formerly codenamed "Raven Ridge") EmbeddedPI-FP5 1213 2026-03-31
AMD Ryzen™ Embedded V2000 Series Processors EmbeddedPI-FP6_1.0.0.D 2026-03-31
AMD Ryzen™ Embedded V3000 Series Processors Embedded-PI_FP7r2 1012 2026-03-31

Revisions

Revision Date Description
2026-04-14 Initial publication

DISCLAIMER

The information contained herein is for informational purposes only and is subject to change without notice. While every precaution has been taken in the preparation of this document, it may contain technical inaccuracies, omissions and typographical errors, and AMD is under no obligation to update or otherwise correct this information. Advanced Micro Devices, Inc. makes no representations or warranties with respect to the accuracy or completeness of the contents of this document, and assumes no liability of any kind, including the implied warranties of noninfringement, merchantability or fitness for particular purposes, with respect to the operation or use of AMD hardware, software or other products described herein. Any computer system has risks of security vulnerabilities that cannot be completely prevented or mitigated. No license, including implied or arising by estoppel, to any intellectual property rights is granted by this document. Terms and limitations applicable to the purchase or use of AMD’s products are as set forth in a signed agreement between the parties or in AMD's Standard Terms and Conditions of Sale.

AMD, the AMD Arrow logo, EPYC, Ryzen, Threadripper, and combinations thereof are trademarks of Advanced Micro Devices, Inc. CVE and the CVE logo are registered trademarks of The MITRE Corporation. Other product names used in this publication are for identification purposes only and may be trademarks of their respective companies.

Third party content may be licensed to you directly by the third party that owns the content and is not licensed to you by AMD. ALL LINKED THIRD-PARTY CONTENT IS PROVIDED ‘AS IS’ WITHOUT A WARRANTY OF ANY KIND. USE OF SUCH THIRD-PARTY CONTENT IS DONE AT YOUR SOLE DISCRETION AND UNDER NO CIRCUMSTANCES WILL AMD BE LIABLE TO YOU FOR ANY THIRD PARTY CONTENT. YOU ASSUME ALL RISK AND ARE SOLELY RESPONSIBILITY FOR ANY DAMAGES THAT MAY ARISE FROM YOUR USE OF THIRD-PARTY CONTENT.

© 2026 Advanced Micro Devices, Inc. All rights reserved.