CVE-2023-31349

Severity
7.8HIGH
EPSS
0.2%
top 63.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 13

Description

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages2 packages

CVEListV5amd/μprof_toolμProf Tool3.4.494
NVDamd/uprof< 4.1.424+2

🔴Vulnerability Details

2
CVEList
CVE-2023-31349: Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting i2024-08-13
GHSA
GHSA-pwh8-gr2w-8xpq: Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting i2024-08-13