CVE-2023-20567

MEDIUM

Intel Radeon RX Vega M Firmware < 23.10.01.46 - Arbitrary Code Execution via Improper Signature Verification

Title source: llm
STIX 2.1

Description

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

Scores

CVSS v3 6.7
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (7)
amd/radeon_pro_vega_56_firmware
amd/radeon_pro_vega_64_firmware
amd/radeon_rx_vega_56_firmware
amd/radeon_rx_vega_64_firmware
amd/radeon_software < 23.7.1
amd/radeon_software < 23.q3
intel/radeon_rx_vega_m_firmware < 23.10.01.46
Published Nov 14, 2023
Tracked Since Feb 18, 2026