CVE-2021-26334: AMD Chipset Driver Information Disclosure Vulnerability
The AMDPowerProfiler.sys driver of AMD ?Prof tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
Other sources
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26334?
CVE-2021-26334 is classified as a high-severity vulnerability due to the potential for privilege escalation and ring-0 code execution.
How do I fix CVE-2021-26334?
To address CVE-2021-26334, users should update the AMD μProf tool to a version later than 3.4.502.
Which systems are affected by CVE-2021-26334?
CVE-2021-26334 affects AMD μProf tool versions prior to 3.4.494 and includes various Windows systems where the driver is installed.
What is the impact of CVE-2021-26334?
CVE-2021-26334 allows lower privileged users to access Machine Specific Registers (MSRs), leading to potential system compromise.
When was CVE-2021-26334 reported?
CVE-2021-26334 was reported in early 2021, highlighting vulnerabilities in the AMD AMDPowerProfiler.sys driver.