An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAmd Radeon Pro W5500
HWAmdall versionsAmd Radeon Pro W5700
HWAmdall versionsAmd Radeon Pro W6300
HWAmdall versionsAmd Radeon Pro W6400
HWAmdall versionsAmd Radeon Pro W6600
HWAmdall versionsAmd Radeon Pro W6800
HWAmdall versionsAmd Radeon Pro W7500
HWAmdall versionsAmd Radeon Pro W7600
HWAmdall versionsAmd Radeon Pro W7800
HWAmdall versionsAmd Radeon Pro W7900
HWAmdall versionsAmd Radeon Rx 5300
HWAmdall versionsAmd Radeon Rx 5300m
HWAmdall versionsAmd Radeon Rx 5300 Xt
HWAmdall versionsAmd Radeon Rx 5500
HWAmdall versionsAmd Radeon Rx 5500m
HWAmdall versionsAmd Radeon Rx 5500 Xt
HWAmdall versionsAmd Radeon Rx 5600
HWAmdall versionsAmd Radeon Rx 5600m
HWAmdall versionsAmd Radeon Rx 5600 Xt
HWAmdall versionsAmd Radeon Rx 5700
HWAmdall versionsAmd Radeon Rx 5700m
HWAmdall versionsAmd Radeon Rx 5700 Xt
HWAmdall versionsAmd Radeon Rx 6300m
HWAmdall versionsAmd Radeon Rx 6400
HWAmdall versionsAmd Radeon Rx 6450m
HWAmdall versionsAmd Radeon Rx 6500m
HWAmdall versionsAmd Radeon Rx 6500 Xt
HWAmdall versionsAmd Radeon Rx 6550m
HWAmdall versionsAmd Radeon Rx 6550s
HWAmdall versionsAmd Radeon Rx 6600
HWAmdall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2023-20596CRITICAL9.8PL ✓same product
Błąd walidacji danych wejściowych w SMM Supervisor procesorów AMD Ryzen
CVE-2023-20586CRITICAL9.8PL ✓same product
Privilege escalation w AMD Radeon Software Crimson ReLive Edition
CVE-2024-36333HIGH7.0same product
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalati...
CVE-2023-31324HIGH7.1same product
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker ...
CVE-2023-20548HIGH7.1same product
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker ...