Insufficient Validation in IOCTL Input/Output Buffer in AMD µProf
CVE-2022-27674

7.5HIGH

Key Information:

Vendor
Amd
Vendor
CVE Published:
9 November 2022

Summary

The vulnerability in AMD µProf arises from insufficient validation in the IOCTL input/output buffer. This flaw can enable an attacker to bypass necessary bounds checks, which may subsequently result in a crash of the Windows kernel. Such an incident leads to denial of service, exposing systems to further risks. It is crucial for users of AMD µProf to implement the latest patches and updates to mitigate this security threat.

Affected Version(s)

AMD μProf AMDuProf_FreeBSD_x64 < 3.6.549

AMD μProf AMDuProf Windows < 3.6.839

AMD μProf AMDuProf Linux < 3.6-449

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.