Untrusted search path in AMD products - CVE-2023-20562
Published: August 8, 2023 / Updated: August 16, 2024
Vulnerability identifier: #VU79248
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20562
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to untrusted search path. A local user can load a malicious driver and execute arbitrary code on the system.
Affected software
AMD uProf for Windows
AMD uProf for FreeBSD
AMD uProf for Linux
AMD uProf for FreeBSD
AMD uProf for Linux
How to mitigate CVE-2023-20562
Install updates from vendor's website.
AMD uProf for Windows - update to 4.1.396
AMD uProf for FreeBSD - update to 4.1.409
AMD uProf for Linux - update to 4.1.424
AMD uProf for FreeBSD - update to 4.1.409
AMD uProf for Linux - update to 4.1.424