CVE-2024-36354: AMD Athlon 3000 Series Desktop Processors With Radeon Graphics

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.

Affected products

  • AMD AMD Athlon 3000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Athlon 3000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Epyc 4004 Series Processors
  • AMD AMD Epyc 7001 Series Processors
  • AMD AMD Epyc 7002 Series Processors
  • AMD AMD Epyc 7003 Series Processors
  • AMD AMD Epyc 8004 Series Processors
  • AMD AMD Epyc 9004 Series Processors
  • AMD AMD Epyc Embedded 3000 Series Processors
  • AMD AMD Epyc Embedded 7002 Series Processors
  • AMD AMD Epyc Embedded 7003 Series Processors
  • AMD AMD Epyc Embedded 9004 Series Processors
  • AMD AMD Epyc Embedded 97x4 Series Processors
  • AMD AMD Ryzen 3000 Series Desktop Processors
  • AMD AMD Ryzen 3000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Desktop Processors
  • AMD AMD Ryzen 4000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processors
  • AMD AMD Ryzen 5000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 6000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7000 Series Desktop Processors
  • AMD AMD Ryzen 7030 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 7035 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7040 Series Mobile Processors With Radeon Graphics
  • and 11 more

Published 2025-09-06. Last modified 2026-06-17.