CVE-2026-0432

HIGH

Amd Ryzen™ 4000 Series Mobile Processors With Radeon™ Graphics - Incorrect Default Permissions

Title source: rule
STIX 2.1

Description

Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.

Scores

CVSS v4 8.5
EPSS 0.0001
EPSS Percentile 2.2%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (46)
AMD/AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics AMD Ryzen™ Chipset Driver 8.01.20.513
AMD/AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics AMD Ryzen™ Chipset Driver 8.01.20.513
AMD/AMD EPYC™ 4004 Series Processors AMD Chipset Driver 8.01.20.513
AMD/AMD EPYC™ 4005 Series Processors AMD Chipset Driver 8.01.20.513
AMD/AMD EPYC™ 7001 Series Processors AMD Server Software 8.03.14.329
AMD/AMD EPYC™ 7002 Series Processors AMD Server Software 8.03.14.329
AMD/AMD EPYC™ 7003 Series Processors AMD Server Software 8.03.14.329
AMD/AMD EPYC™ 8004 Series Processors AMD Server Software 8.03.16.641
AMD/AMD EPYC™ 9004 Series Processors AMD Server Software 8.03.16.641
AMD/AMD EPYC™ 9005 Series Processors AMD Server Software 8.03.16.641
... and 36 more
Published May 15, 2026
Tracked Since May 15, 2026