CVE-2024-36340
- EPSS 0.02%
- Published 13.05.2025 14:15:19
- Last modified 13.05.2025 19:35:18
A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.
CVE-2023-20556
- EPSS 0.04%
- Published 08.08.2023 18:15:11
- Last modified 21.11.2024 07:41:06
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.
CVE-2023-20561
- EPSS 0.04%
- Published 08.08.2023 18:15:11
- Last modified 21.11.2024 07:41:07
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service.
CVE-2023-20562
- EPSS 8.43%
- Published 08.08.2023 18:15:11
- Last modified 21.11.2024 07:41:07
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
CVE-2022-27674
- EPSS 0.09%
- Published 09.11.2022 21:15:14
- Last modified 01.05.2025 15:15:54
Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.
CVE-2022-23831
- EPSS 0.22%
- Published 09.11.2022 21:15:13
- Last modified 01.05.2025 15:15:54
Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.
CVE-2021-26334
- EPSS 0.51%
- Published 01.12.2021 16:15:07
- Last modified 21.11.2024 05:56:07
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.