CVE-2023-20567
published 2023-11-14CVE-2023-20567: Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch…
PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.16%
5.4th percentile
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | radeon_pro_w5000_w6000_w7000_series_graphics_cards | — | — |
| amd | radeon_pro_wx_vega_series_graphics_cards | — | — |
| amd | radeon_rx_5000_6000_7000_series_graphics_cards | — | — |
| amd | radeon_rx_vega_series_graphics_cards | — | — |
| amd | radeon_software | < 23.7.1 | 23.7.1 |
| amd | radeon_software | < 23.q3 | 23.q3 |
| intel | radeon_rx_vega_m_firmware | < 23.10.01.46 | 23.10.01.46 |
| linux | linux_kernel | >= 0 < 4.4.0-252.286 | 4.4.0-252.286 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-aws vulnerabilities
osv·2024-03-21·CVSS 6.4
CVE-2022-20567 linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the Layer 2 Tunneling Protocol (L2TP) implementation
in the Linux kernel contained a race condition when releasing PPPoL2TP
sockets in certain conditions, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2022-20567)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle block device modification while it is
mounted. A privileged attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-34256)
Eric Dumazet discovered that the netfilter subsystem in the Linux kernel
did not properly handle DCCP conntrack buffers in certain
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-03-18·CVSS 6.4
CVE-2022-20567 linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that the Layer 2 Tunneling Protocol (L2TP) implementation
in the Linux kernel contained a race condition when releasing PPPoL2TP
sockets in certain conditions, leading to a use-after-free vulnerability.
A local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2022-20567)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle block device modification while it is
mounted. A privileged attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-34256)
Eric Dumazet discovered that the netfilter subsystem in the Linux kernel
did not properly handl
GHSA
GHSA-x8xw-jc3c-cx53: Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareIns
ghsa_unreviewed·2023-11-14
CVE-2023-20567 [MEDIUM] CWE-347 GHSA-x8xw-jc3c-cx53: Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareIns
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.htmlhttps://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.html
2023-11-14
Published