CVE-2024-21925: AMD Athlon 3000 Series Desktop Processors With Radeon Graphics

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.

Affected products

  • AMD AMD Athlon 3000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Athlon 3000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Epyc 7001 Processors
  • AMD AMD Epyc 7002 Processors
  • AMD AMD Epyc 7003 Processors
  • AMD AMD Epyc 9004 Processors
  • AMD AMD Epyc Embedded 3000
  • AMD AMD Epyc Embedded 7002
  • AMD AMD Epyc Embedded 7003
  • AMD AMD Epyc Embedded 9004
  • AMD AMD Ryzen 3000 Series Desktop Processors
  • AMD AMD Ryzen 3000 Series Mobile Processor With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Desktop Processor With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processor With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processors
  • AMD AMD Ryzen 5000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 6000 Series Processor With Radeon Graphics
  • AMD AMD Ryzen 7000 Series Desktop Processors
  • AMD AMD Ryzen 7000 Series Mobile Processors
  • AMD AMD Ryzen 7020 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7035 Series Processor With Radeon Graphics
  • AMD AMD Ryzen 7040 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 8000 Series Processor With Radeon Graphics
  • AMD AMD Ryzen 8040 Series Mobile Processors With Radeon Graphics
  • and 12 more

Published 2025-02-11. Last modified 2026-06-17.