← back
CVE-2023-20562

EPSS 1.1%
In short

AMD uProf has a flaw in how it validates commands sent to it by programs, allowing an authenticated user to load a driver without proper verification. This could let someone run malicious code with the highest level of system access.

Technical detail

The vulnerability exists in IOCTL input buffer validation within AMD uProf, where insufficient sanitization of user-supplied data allows an authenticated attacker to load unsigned kernel drivers. This bypasses driver signature verification mechanisms, potentially enabling arbitrary kernel-mode code execution with system privileges.

Summary generated and translated by AI from the official description.
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
Affected products
AMD · μProf

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →