First published: Tue Nov 09 2021(Updated: )
The AMDPowerProfiler.sys driver of AMD ?Prof tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
<3.4.494 | ||
<3.4.502 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26334 is classified as a high-severity vulnerability due to the potential for privilege escalation and ring-0 code execution.
To address CVE-2021-26334, users should update the AMD μProf tool to a version later than 3.4.502.
CVE-2021-26334 affects AMD μProf tool versions prior to 3.4.494 and includes various Windows systems where the driver is installed.
CVE-2021-26334 allows lower privileged users to access Machine Specific Registers (MSRs), leading to potential system compromise.
CVE-2021-26334 was reported in early 2021, highlighting vulnerabilities in the AMD AMDPowerProfiler.sys driver.