CVE-2025-29950 is an improper input validation vulnerability in System Management Mode (SMM) that could allow a privileged attacker to overwrite stack memory, leading to arbitrary code execution. This vulnerability has a high CVSS score of 7.1, indicating a significant risk, and requires high privileges and high attack complexity to exploit. There is currently no public exploit code available, nor is there any indication of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | AMD EPYC™ 7001 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7002 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7003 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 9004 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 9005 Series Processors | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.