CVE-2022-27674: Input Validation
Insufficient validation in the IOCTL input/output buffer in AMD ?Prof may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.
Other sources
Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27674?
CVE-2022-27674 is a vulnerability in AMD ?Prof that allows an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.
What software is affected by CVE-2022-27674?
The affected software is AMD ?Prof version up to exclusive 3.6.549.
How can an attacker exploit CVE-2022-27674?
An attacker can exploit CVE-2022-27674 by bypassing bounds checks in AMD ?Prof and causing a Windows kernel crash.
What is the severity of CVE-2022-27674?
The severity of CVE-2022-27674 is high with a severity value of 7.5.
Where can I find more information about CVE-2022-27674?
You can find more information about CVE-2022-27674 on the AMD Product Security Bulletin at https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1046.