CVE-2023-20556: Medium severity amd uprof vulnerability
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD ?Prof may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.
Other sources
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20556?
CVE-2023-20556 is a vulnerability in AMD ?Prof that allows an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.
How severe is CVE-2023-20556?
CVE-2023-20556 has a severity level of medium (5.5).
Which software is affected by CVE-2023-20556?
The affected software is AMD ?Prof version up to 4.1.396.
Is Microsoft Windows affected by CVE-2023-20556?
No, Microsoft Windows is not vulnerable to CVE-2023-20556.
Is the Linux Kernel affected by CVE-2023-20556?
No, the Linux Kernel is not vulnerable to CVE-2023-20556.
How can I fix CVE-2023-20556?
To fix CVE-2023-20556, update AMD ?Prof to version 4.1-424 or later.