CVE-2020-12891: High severity amd radeon pro software vulnerability
Published Feb 4, 2022
·Updated
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
Affected Software
2 affected components
AMD Radeon Pro Software<21.q2
AMD Radeon Software<21.4.1
Event History
Feb 4, 2022
CVE Published
via MITRE·10:29 PM
Data Sourced
via MITRE·10:29 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-12891.
2
What is the severity of CVE-2020-12891?
The severity of CVE-2020-12891 is high (7.8).
3
What is the affected software of CVE-2020-12891?
The affected software of CVE-2020-12891 is AMD Radeon Software (up to version 21.4.1) and AMD Radeon Pro Software (up to version 21.q2).
4
How does CVE-2020-12891 exploit DLL Hijacking?
CVE-2020-12891 exploits DLL Hijacking by allowing an unprivileged user to drop a malicious DLL file in a location that is in the path environment variable.
5
Where can I find more information about CVE-2020-12891?
You can find more information about CVE-2020-12891 on the AMD Product Security Bulletin at https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1000.