A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAmd Cleanup Utility
APPAmd25.20.00.00Amd Radeon Pro Vii
HWAmdall versionsAmd Radeon Pro W5500
HWAmdall versionsAmd Radeon Pro W5500x
HWAmdall versionsAmd Radeon Pro W5700
HWAmdall versionsAmd Radeon Pro W5700x
HWAmdall versionsAmd Radeon Pro W6300
HWAmdall versionsAmd Radeon Pro W6300m
HWAmdall versionsAmd Radeon Pro W6400
HWAmdall versionsAmd Radeon Pro W6500m
HWAmdall versionsAmd Radeon Pro W6600
HWAmdall versionsAmd Radeon Pro W6600m
HWAmdall versionsAmd Radeon Pro W6600x
HWAmdall versionsAmd Radeon Pro W6800
HWAmdall versionsAmd Radeon Pro W6800x
HWAmdall versionsAmd Radeon Pro W6800x Duo
HWAmdall versionsAmd Radeon Pro W6900x
HWAmdall versionsAmd Radeon Software
APPAmd< 25.q3.1< 26.q1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
Related vulnerabilities
CVE-2023-20586CRITICAL9.8PL ✓same product
Privilege escalation w AMD Radeon Software Crimson ReLive Edition
CVE-2023-31324HIGH7.1same product
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker ...
CVE-2023-20548HIGH7.1same product
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker ...
CVE-2024-21937HIGH7.3same product
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve pri...
CVE-2023-31320HIGH7.5same product
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the dis...