CVE-2021-26334

The AMDPowerProfiler.sys driver of AMD µProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:amd:amd_uprof:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:amd:amd_uprof:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:56

Type Values Removed Values Added
References () https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1016 - Mitigation, Vendor Advisory () https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1016 - Mitigation, Vendor Advisory

07 Nov 2023, 03:31

Type Values Removed Values Added
Summary The AMDPowerProfiler.sys driver of AMD ?Prof tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user. The AMDPowerProfiler.sys driver of AMD µProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.

Information

Published : 2021-12-01 16:15

Updated : 2024-11-21 05:56


NVD link : CVE-2021-26334

Mitre link : CVE-2021-26334

CVE.ORG link : CVE-2021-26334


JSON object : View

Products Affected

linux

  • linux_kernel

microsoft

  • windows

amd

  • amd_uprof
CWE
CWE-284

Improper Access Control

NVD-CWE-Other