CVE-2025-48510 describes an improper return value vulnerability in AMD uProf, allowing a local attacker to bypass Kernel Space Layout Randomization (KSLR). This flaw carries a CVSS score of 7.1 (HIGH), indicating a low attack complexity and requiring local privileges, with potential impacts on confidentiality and availability. While the FAUCET Risk Score is 83/100, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.1174CPE matchmatch criteria | cpe:2.3:a:amd:uprof:*:*:*:*:*:windows:*:* | ||
< 5.0.1223CPE matchmatch criteria | cpe:2.3:a:amd:uprof:*:*:*:*:*:freebsd:*:* | ||
< 5.0.1479CPE matchmatch criteria | cpe:2.3:a:amd:uprof:*:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.