Cryptographic Signature Vulnerability in AMD Radeon RGB Tool
CVE-2024-36334

7HIGH

What is CVE-2024-36334?

The Radeon RGB Tool by AMD contains a flaw that arises from improper verification of cryptographic signatures. This weakness enables a malicious file within the installation directory to be executed with elevated privileges, leading to potential arbitrary code execution. Immediate updates and security measures are recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

AMD Radeon™ RX 7000 Series Graphics Products amd_rx_7900_xtx_rgb_led_20241008.exe “AMD Radeon RX 7900 XTX RGB Tool” available at https://www.amd.com/en/support/downloads/drivers.html/graphics/radeon-rx/radeon-rx-7000-series/amd-radeon-rx-7900-xtx.html

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.