Database/Control plane, storage & DevOps
AMD Radeon RX Vega M graphics driver installer - signature verification: The driver package launches
Impact
The driver package launches AMDSoftwareInstaller.exe without validating its signature, so an attacker with admin privileges can substitute the binary and get their code run by a trusted installer flow. It is a signed-update-chain failure rather than a memory-safety bug: the mechanism you use to keep drivers current is the mechanism that runs the attacker's payload.
Who can reach it
Local, requires admin privilege to place the substituted binary. Windows driver packaging.
What to do
Update the AMD driver package. Relevant only where you deploy AMD's Windows driver installer; Linux ROCm deployments are unaffected.
References
Related entries
- Intel oneAPI compiler: An uncontrolled library search path: the component loads a shared library by nameCVE-2024-21857 · Intel oneAPI compilerMedium
- Intel oneAPI Level Zero software: An uncontrolled search path in Level Zero lets an authenticated local user get codeCVE-2024-31073 · Intel oneAPI Level Zero softwareMedium
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameCVE-2024-47795 · Intel oneAPI DPC++/C++ compilerMedium
- Intel oneAPI toolkit and component installers: An uncontrolled library search path: the component loads a sharedCVE-2025-20017 · Intel oneAPI toolkit and component installersMedium
- Intel oneAPI DPC++/C++ compiler installer: The compiler installer sets permissions that let a local user modifyCVE-2025-20087 · Intel oneAPI DPC++/C++ compiler installerMedium
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameCVE-2025-20627 · Intel oneAPI DPC++/C++ compilerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.