Improper Signature Verification in Radeon Graphics Driver by AMD
CVE-2023-20567
6.7MEDIUM
Key Information:
- Vendor
- Amd
- Status
- Vendor
- CVE Published:
- 14 November 2023
Summary
The Radeon RX Vega M Graphics driver for Windows contains an improper signature verification flaw that may permit an attacker with administrative privileges to execute the AMDSoftwareInstaller.exe file without proper file signature validation, potentially leading to arbitrary code execution. This vulnerability poses a significant risk as it allows malicious actors to exploit the system, particularly in environments where users may have elevated permissions.
Affected Version(s)
Radeon™ PRO W5000/W6000/W7000 Series Graphics Cards x86 various
Radeon™ PRO WX Vega Series Graphics Cards x86 various
Radeon™ RX 5000/6000/7000 Series Graphics Cards x86 various
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved