CVE-2023-20562: High severity amd uprof vulnerability
Published Aug 8, 2023
·Updated
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
Affected Software
4 affected components
AMD AMD uProf<4.1.396
Microsoft Windows
AMD AMD uProf<4.1-424
Linux Linux kernel
Remediation
Event History
Aug 8, 2023
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-20562.
2
What is the severity of CVE-2023-20562?
The severity of CVE-2023-20562 is high with a CVSS score of 7.8.
3
What is the affected software?
The affected software is AMD uProf 4.1.396 up to exclusive 4.1-424.
4
What is the impact of this vulnerability?
This vulnerability in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
5
Is Linux Kernel affected by this vulnerability?
No, Linux Kernel is not affected by this vulnerability.