AMD VCN FW Debug Code Enables HW Register R/W Exploit
CVE-2024-36319 Published on February 12, 2026
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
Weakness Type
Exposed Chip Debug and Test Interface With Insufficient or Missing Authorization
The chip does not implement or does not correctly check whether users are authorized to access internal registers.
Affected Versions
AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics; AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics:- Version AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 is unaffected.
- Version AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 is unaffected.
- Version AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 is unaffected.
- Version AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 is unaffected.
- Version Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Catalyst™ driver [25.6.1] (68926) is unaffected.
- Version Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Catalyst™ driver [25.6.1] (68926) is unaffected.
- Version Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Catalyst™ driver [25.6.1] (68926) is unaffected.
- Version 25.5.1 (25.10.01.09), AMD Software: PRO Edition 25.Q2(25.10.10), Radeon Software For Linux 25.10.1 is unaffected.
- Version 25.5.1 (25.10.01.09), AMD Software: PRO Edition 25.Q2(25.10.10), Radeon Software For Linux 25.10.1 is unaffected.
- Version ROCm 6.2.4 is unaffected.
- Version ROCm 6.2.4 is unaffected.
- Version ROCm 6.2.4 is unaffected.
- Version ROCm 6.2.4 is unaffected.
- Version Contact your AMD Customer Engineering representative is unaffected.
Exploit Probability
EPSS
0.01%
Percentile
1.62%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.