Radeon Software
by AMD
CVEs (52)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-20586 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations | ||
| CVE-2024-36333 | Hig | 0.51 | 7.8 | 0.00 | May 15, 2026 | A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | ||
| CVE-2023-31324 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or… | ||
| CVE-2023-20548 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability. | ||
| CVE-2023-20598 | Hig | 0.51 | 7.8 | 0.00 | Oct 17, 2023 | An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution. | ||
| CVE-2021-26392 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA. | ||
| CVE-2021-26391 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel. | ||
| CVE-2021-26360 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP. | ||
| CVE-2020-12931 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | ||
| CVE-2020-12930 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | ||
| CVE-2021-26317 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. | ||
| CVE-2021-26369 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. | ||
| CVE-2020-12891 | Hig | 0.51 | 7.8 | 0.00 | Feb 4, 2022 | AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable. | ||
| CVE-2020-12962 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Escape call interface in the AMD Graphics Driver for Windows may cause privilege escalation. | ||
| CVE-2020-12903 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12893 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12898 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12892 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution. | ||
| CVE-2020-12963 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system. | ||
| CVE-2020-12929 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution . |
- risk 0.64cvss 9.8epss 0.01
A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations
- risk 0.51cvss 7.8epss 0.00
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or…
- risk 0.51cvss 7.8epss 0.00
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
- risk 0.51cvss 7.8epss 0.00
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.
- risk 0.51cvss 7.8epss 0.00
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.
- risk 0.51cvss 7.8epss 0.00
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.
- risk 0.51cvss 7.8epss 0.00
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
- risk 0.51cvss 7.8epss 0.00
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
- risk 0.51cvss 7.8epss 0.00
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.
- risk 0.51cvss 7.8epss 0.00
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
- risk 0.51cvss 7.8epss 0.00
Escape call interface in the AMD Graphics Driver for Windows may cause privilege escalation.
- risk 0.51cvss 7.8epss 0.00
Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.
- risk 0.51cvss 7.8epss 0.00
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.
- risk 0.51cvss 7.8epss 0.00
Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution .
Page 1 of 3