CVE-2023-31341

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
13/08/2024
Last modified:
26/02/2025

Description

Insufficient<br /> validation of the Input Output Control (IOCTL) input buffer in AMD μProf may<br /> allow an authenticated attacker to cause an out-of-bounds write, potentially<br /> causing a Windows® OS crash, resulting in denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amd:uprof:*:*:*:*:*:linux:*:* 4.1.424 (excluding)
cpe:2.3:a:amd:uprof:*:*:*:*:*:freebsd:*:* 4.2.816 (excluding)
cpe:2.3:a:amd:uprof:*:*:*:*:*:windows:*:* 4.2.845 (excluding)