First published: Mon May 18 2020(Updated: )
An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x81112ee0 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AMD OverDrive |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7247 has a high severity rating due to its potential for arbitrary code execution and privilege escalation.
To fix CVE-2019-7247, ensure that you update the AMD OverDrive software to the latest version with the necessary security patches.
CVE-2019-7247 affects systems running AMD OverDrive that utilize the AODDriver2.sys driver.
CVE-2019-7247 can be exploited to allow arbitrary Model Specific Register (MSR) writes, leading to Ring-0 code execution.
The vendor for CVE-2019-7247 is AMD, with the vulnerability stemming from their OverDrive software.