Database/Control plane, storage & DevOps
AMD Radeon RX Vega M graphics driver installer - signature verification: The driver package launches
Impact
The driver package launches AMDSoftwareInstaller.exe without validating its signature, so an attacker with admin privileges can substitute the binary and get their code run by a trusted installer flow. It is a signed-update-chain failure rather than a memory-safety bug: the mechanism you use to keep drivers current is the mechanism that runs the attacker's payload.
Who can reach it
Local, requires admin privilege to place the substituted binary. Windows driver packaging.
What to do
Update the AMD driver package. Relevant only where you deploy AMD's Windows driver installer; Linux ROCm deployments are unaffected.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.