GPU VulnDB

Database/Control plane, storage & DevOps

AMD Radeon RX Vega M graphics driver installer - signature verification: The driver package launches

CVE-2023-20567Control plane, storage & DevOpscurated

Impact

The driver package launches AMDSoftwareInstaller.exe without validating its signature, so an attacker with admin privileges can substitute the binary and get their code run by a trusted installer flow. It is a signed-update-chain failure rather than a memory-safety bug: the mechanism you use to keep drivers current is the mechanism that runs the attacker's payload.

Who can reach it

Local, requires admin privilege to place the substituted binary. Windows driver packaging.

What to do

Update the AMD driver package. Relevant only where you deploy AMD's Windows driver installer; Linux ROCm deployments are unaffected.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.