CVE-2023-20567

6.7MEDIUM

Key Information

Vendor
AMD
Status
Radeon™ RX 5000/6000/7000 Series Graphics Cards
Radeon™ PRO W5000/W6000/W7000 Series Graphics Cards
Radeon™ RX Vega Series Graphics Cards
Radeon™ PRO WX Vega Series Graphics Cards
Vendor
CVE Published:
14 November 2023

Summary

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

Affected Version(s)

Radeon™ RX 5000/6000/7000 Series Graphics Cards = various

Radeon™ PRO W5000/W6000/W7000 Series Graphics Cards = various

Radeon™ RX Vega Series Graphics Cards = various

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.