DLL Hijacking Vulnerability in AMD Radeon Software
CVE-2020-12891
7.8HIGH
Key Information:
- Vendor
- Amd
- Vendor
- CVE Published:
- 4 February 2022
Summary
AMD Radeon Software is susceptible to a DLL Hijacking vulnerability stemming from improper handling of the path environment variable. This issue allows an unprivileged user to potentially place a malicious DLL file in a writable location included in the path variable. As a result, upon execution, the software may inadvertently load the malicious DLL, leading to unauthorized actions. It's crucial for users to be aware of this vulnerability to safeguard their systems against potential exploits.
Affected Version(s)
Radeon Pro Software for Enterprise Enterprise Driver < 21.Q2
Radeon Software Radeon Driver < 21.4.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved