PT-2021-8203 · Amd+1 · Amd Μprof+1
Michal Posluå¡Nã½
·
Published
2021-11-09
·
Updated
2024-12-09
·
CVE-2021-26334
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AMD μProf tool (affected versions not specified)
Description
The AMDPowerProfiler.sys driver of the AMD μProf tool may allow lower privileged users to access MSRs in the kernel, which may lead to privilege escalation and ring-0 code execution by the lower privileged user. The vulnerability is related to insufficient access control and can be exploited by an attacker to gain access to registers without proper privileges, potentially leading to code execution with ring-0 privileges. More than 10 serious errors were fixed in the graphical drivers for Windows 10, including this vulnerability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amd Μprof
Red Os