CVE-2023-20568

MEDIUM

Intel Radeon RX Vega M Firmware < 23.10.01.46 - Authenticated Arbitrary Code Execution via Unverified Driver Signature

Title source: llm
STIX 2.1

Description

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

Scores

CVSS v3 6.7
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (7)
amd/radeon_pro_vega_56_firmware
amd/radeon_pro_vega_64_firmware
amd/radeon_rx_vega_56_firmware
amd/radeon_rx_vega_64_firmware
amd/radeon_software < 23.7.1
amd/radeon_software < 23.q3
intel/radeon_rx_vega_m_firmware < 23.10.01.46
Published Nov 14, 2023
Tracked Since Feb 18, 2026