Improper Signature Verification in Radeon Graphics Driver by AMD
CVE-2023-20567

6.7MEDIUM

Summary

The Radeon RX Vega M Graphics driver for Windows contains an improper signature verification flaw that may permit an attacker with administrative privileges to execute the AMDSoftwareInstaller.exe file without proper file signature validation, potentially leading to arbitrary code execution. This vulnerability poses a significant risk as it allows malicious actors to exploit the system, particularly in environments where users may have elevated permissions.

Affected Version(s)

Radeon™ PRO W5000/W6000/W7000 Series Graphics Cards x86 various

Radeon™ PRO WX Vega Series Graphics Cards x86 various

Radeon™ RX 5000/6000/7000 Series Graphics Cards x86 various

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.