7.8

CVE-2023-20562



Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.

















Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Amd Uprof Version < 4.1.396
   Microsoft ≫ Windows Version -
Amd ≫ Amd Uprof Version < 4.1-424
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.589
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7003
Patch
Vendor Advisory