SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12891

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable.

HIGH 7.8EPSS 0.25%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.25% probability · 17th percentile
CISA KEV
Not listed
Weakness
CWE-427
Affected
amd/radeon pro software · amd/radeon software
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.