CVE-2023-20562
In short
AMD uProf has a flaw in how it validates commands sent to it by programs, allowing an authenticated user to load a driver without proper verification. This could let someone run malicious code with the highest level of system access.
Technical detail
The vulnerability exists in IOCTL input buffer validation within AMD uProf, where insufficient sanitization of user-supplied data allows an authenticated attacker to load unsigned kernel drivers. This bypasses driver signature verification mechanisms, potentially enabling arbitrary kernel-mode code execution with system privileges.
Summary generated and translated by AI from the official description.
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
Affected products
AMD · μProfWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →