CVE-2023-20562
HIGHAMD uProf < 4.1.396 - Authenticated Arbitrary Kernel Execution via IOCTL Input Buffer
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-20562. PoCs published by zeze-zeze, passwa11.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-20562, targeting AMD μProf's AMDCpuProfiler.sys driver to achieve privilege escalation to SYSTEM via arbitrary write on the EPROCESS token. It also includes a BYOVD (Bring Your Own Vulnerable Driver) component to disable DSE and bypass 360 Total Security protections.
Description
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
Exploits (2)
This repository contains a functional exploit for CVE-2023-20562, targeting AMD μProf's AMDCpuProfiler.sys driver to achieve privilege escalation to SYSTEM via arbitrary write on the EPROCESS token. It also includes a BYOVD (Bring Your Own Vulnerable Driver) component to disable DSE and bypass 360 Total Security protections.
This repository contains a functional exploit for CVE-2023-20562, targeting AMD μProf's AMDCpuProfiler.sys driver to achieve privilege escalation to SYSTEM via arbitrary write on the EPROCESS token. It also includes a BYOVD (Bring Your Own Vulnerable Driver) component to disable DSE and bypass 360 Total Security protections.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H