Database/Control plane, storage & DevOps
AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that map
Impact
The AMD ATI atillk64.sys driver exposes routines that map physical memory into a caller's virtual address space, and it lets low-privileged users call them. That is arbitrary physical memory read and write handed to any local user - complete bypass of kernel memory protection with no memory-corruption exploit required, because the driver simply offers the capability. Drivers like this are a favourite BYOVD (bring-your-own-vulnerable-driver) primitive precisely because they are signed and they work as designed.
Who can reach it
Local, low-privileged user with the driver loaded. Windows driver; note that an attacker can also *bring* this driver to a host that never shipped it, which is why it matters even if you do not deploy AMD's Windows tooling.
What to do
Remove or update the driver. On Windows fleets, add atillk64.sys to your vulnerable-driver blocklist (Microsoft's WDAC blocklist covers this class) rather than relying on it not being installed - the BYOVD path means an attacker supplies the driver themselves. Not applicable to Linux ROCm nodes.
References
Related entries
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateCVE-2020-12347 · Intel Data Center Manager ConsoleHigh
- Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the managementCVE-2020-17389 · Marvell QConvergeConsole (QLogic adapter management)High
- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureCVE-2020-25660 · Ceph CephX authentication protocolHigh
- APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reportsCVE-2020-7526 · APC PowerChute Business Edition (v9.0.x and earlier)High
- Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadCVE-2020-7569 · Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1High
- Nagios XI: OS command injection in the windowswmi config wizard (authenticated)CVE-2021-25296 · Nagios XIHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.