Lenovo update for AMD Radeon Graphics Kernel driver



| Updated: 2025-05-21
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-20598
CWE-ID CWE-782
Exploitation vector Local
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
ThinkStation P358 Workstation
Hardware solutions / Firmware

ThinkStation P620 Workstation
Hardware solutions / Firmware

ThinkStation P360 Ultra Workstation
Hardware solutions / Firmware

ThinkStation P7 Intel Workstation
Hardware solutions / Firmware

ThinkStation P5 Workstation
Hardware solutions / Firmware

ThinkStation P920 Workstation
Hardware solutions / Firmware

ThinkStation P720 Workstation
Hardware solutions / Firmware

ThinkStation P520c Workstation
Hardware solutions / Firmware

ThinkStation P520 Workstation
Hardware solutions / Firmware

ThinkStation P360 Workstation
Hardware solutions / Firmware

ThinkStation P350 Workstation
Hardware solutions / Firmware

ThinkStation P348 Workstation
Hardware solutions / Firmware

ThinkStation P3 Tower Workstation
Hardware solutions / Firmware

ThinkStation P340 Workstation
Hardware solutions / Firmware

AMD Graphic Driver for WX3200 for Windows 10 (Version 22H2), 11 (Version 22H2 or Later) - ThinkStation P920, P720, P520, P520c
Hardware solutions / Drivers

AMD Discrete Graphics Legacy Driver for Windows 10-64-bit (Version 1909) - ThinkStation P520, P520c, P720, P920
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 RS4 (64-bit) - ThinkStation P520, P520c, P720, P920
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 20H2) - ThinkStation P920, P720, P520, P520c
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 2004) - ThinkStation P520, P520c, P720, P920
Hardware solutions / Drivers

AMD Discrete Graphic Driver for Windows 10 (Version 21H2), 11 (Version 21H2 or later) - ThinkStation P520, P520c, P720, P920
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 22H2) - ThinkStation P360
Hardware solutions / Drivers

AMD Discrete Graphics Driver (Radeon W6400) for Windows 10 (Version 20H2, 21H1, 21H2) - ThinkStation P360
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 11 (Version 21H2), 10 (Version 21H2) - ThinkStation P360 Ultra
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 IOT - ThinkStation P360 Ultra
Hardware solutions / Drivers

AMD Discrete Graphics Driver For W6400 for Windows 10 (Version 21H2)- ThinkStation P360 Ultra
Hardware solutions / Drivers

AMD Discrete Driver for Windows 11 (Version 21H2), 10 (Version 21H2) - ThinkStation P358
Hardware solutions / Drivers

AMD Discrete VGA Driver for Windows 10 64-bit (Version 20H2) - ThinkStation P348
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 11 (Version 21H2 or Later) - ThinkStation P348
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 21H2) - ThinkStation P348
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 21H2, 22H2), 11 (Version 21H2, 22H2, 23H2) - ThinkStation P3
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 21H1), 11 (Version 21H2 or Later) - ThinkStation P350
Hardware solutions / Drivers

AMD Discrete Graphics Driver (Radeon W6400) for Windows 10 (Version 21H2), 11 (Version 21H2) - ThinkStation P348
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 11 (Version 21H2 or Later) - ThinkStation P340
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 21H2) - ThinkStation P340
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 21H2), 11 (Version 21H2, 22H2) - ThinkStation P7 Intel
Hardware solutions / Drivers

AMD Discrete VGA Driver for Windows 11 (Version 22H2) - ThinkStation P620
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 10 (Version 21H2), 11 (Version 21H2, 22H2) - ThinkStation P5
Hardware solutions / Drivers

AMD Discrete Graphics Driver for W6400 for Windows 10 (Version 21H2, 22H2 or Later) - ThinkStation P360 Ultra
Hardware solutions / Drivers

AMD Discrete Graphics Driver for Windows 11 (Version 22H2 or Later), 10 (Version 22H2) - ThinkStation P358
Hardware solutions / Drivers

AMD Discrete VGA Driver for Windows 10 64-bit (Version 20H2) - ThinkStation P350
Hardware solutions / Drivers

AMD Discrete VGA Driver for Windows 10 64-bit (Version 20H2) - ThinkStation P340
Hardware solutions / Drivers

AMD Discrete VGA Driver for Windows 10 64-bit (Version 2004) - ThinkStation P340
Hardware solutions / Drivers

Vendor Lenovo

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Exposed IOCTL with Insufficient Access Control

EUVDB-ID: #VU82434

Risk: Low

CVSSv4.0: 7.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear]

CVE-ID: CVE-2023-20598

CWE-ID: CWE-782 - Exposed IOCTL with Insufficient Access Control

Exploit availability: Yes

Description

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to insufficient access control in the IOCTL within the pdfwkrnl.sys driver. A local user can send a specially crafted IOCTL request and execute abitrary code on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

ThinkStation P358 Workstation: All versions

ThinkStation P620 Workstation: All versions

ThinkStation P360 Ultra Workstation: All versions

ThinkStation P7 Intel Workstation: All versions

ThinkStation P5 Workstation: All versions

ThinkStation P920 Workstation: All versions

ThinkStation P720 Workstation: All versions

ThinkStation P520c Workstation: All versions

ThinkStation P520 Workstation: All versions

ThinkStation P360 Workstation: All versions

ThinkStation P350 Workstation: All versions

ThinkStation P348 Workstation: All versions

ThinkStation P3 Tower Workstation: All versions

ThinkStation P340 Workstation: All versions

AMD Graphic Driver for WX3200 for Windows 10 (Version 22H2), 11 (Version 22H2 or Later) - ThinkStation P920, P720, P520, P520c: before 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Legacy Driver for Windows 10-64-bit (Version 1909) - ThinkStation P520, P520c, P720, P920: before 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver for Windows 10 RS4 (64-bit) - ThinkStation P520, P520c, P720, P920: before 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver for Windows 10 (Version 20H2) - ThinkStation P920, P720, P520, P520c: before 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver for Windows 10 (Version 2004) - ThinkStation P520, P520c, P720, P920: before 31.0.21912.14 FOR WX3200

AMD Discrete Graphic Driver for Windows 10 (Version 21H2), 11 (Version 21H2 or later) - ThinkStation P520, P520c, P720, P920: before 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver for Windows 10 (Version 22H2) - ThinkStation P360: before 31.0.14037.18001

AMD Discrete Graphics Driver (Radeon W6400) for Windows 10 (Version 20H2, 21H1, 21H2) - ThinkStation P360: before 31.0.14037.18001

AMD Discrete Graphics Driver for Windows 11 (Version 21H2), 10 (Version 21H2) - ThinkStation P360 Ultra: before 31.0.24026.3002 FOR W6400 AND 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver for Windows 10 IOT - ThinkStation P360 Ultra: before 31.0.24026.3002 FOR W6400 AND 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver For W6400 for Windows 10 (Version 21H2)- ThinkStation P360 Ultra: before 31.0.24026.3002

AMD Discrete Driver for Windows 11 (Version 21H2), 10 (Version 21H2) - ThinkStation P358: before 31.0.24026.3002

AMD Discrete VGA Driver for Windows 10 64-bit (Version 20H2) - ThinkStation P348: before 31.0.21916.4001

AMD Discrete Graphics Driver for Windows 11 (Version 21H2 or Later) - ThinkStation P348: before 31.0.21916.4001

AMD Discrete Graphics Driver for Windows 10 (Version 21H2) - ThinkStation P348: before 31.0.21916.4001

AMD Discrete Graphics Driver for Windows 10 (Version 21H2, 22H2), 11 (Version 21H2, 22H2, 23H2) - ThinkStation P3: before 31.0.14037.18001

AMD Discrete Graphics Driver for Windows 10 (Version 21H1), 11 (Version 21H2 or Later) - ThinkStation P350: before 31.0.21916.4001

AMD Discrete Graphics Driver (Radeon W6400) for Windows 10 (Version 21H2), 11 (Version 21H2) - ThinkStation P348: before 30.0.14014.3001

AMD Discrete Graphics Driver for Windows 11 (Version 21H2 or Later) - ThinkStation P340: before 31.0.21916.4001

AMD Discrete Graphics Driver for Windows 10 (Version 21H2) - ThinkStation P340: before 31.0.21916.4001

AMD Discrete Graphics Driver for Windows 10 (Version 21H2), 11 (Version 21H2, 22H2) - ThinkStation P7 Intel: before 32.0.11002.41

AMD Discrete VGA Driver for Windows 11 (Version 22H2) - ThinkStation P620: before 31.0.24026.3002

AMD Discrete Graphics Driver for Windows 10 (Version 21H2), 11 (Version 21H2, 22H2) - ThinkStation P5: before 32.0.11002.41

AMD Discrete Graphics Driver for W6400 for Windows 10 (Version 21H2, 22H2 or Later) - ThinkStation P360 Ultra: before 31.0.24026.3002 FOR W6400 AND 31.0.21912.14 FOR WX3200

AMD Discrete Graphics Driver for Windows 11 (Version 22H2 or Later), 10 (Version 22H2) - ThinkStation P358: before 31.0.24026.3002

AMD Discrete VGA Driver for Windows 10 64-bit (Version 20H2) - ThinkStation P350: before 31.0.21916.4001

AMD Discrete VGA Driver for Windows 10 64-bit (Version 20H2) - ThinkStation P340: before 31.0.21916.4001

AMD Discrete VGA Driver for Windows 10 64-bit (Version 2004) - ThinkStation P340: before 31.0.21916.4001

CPE2.3 External links

https://support.lenovo.com/us/en/product_security/LEN-142133


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###