A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
During installation, installed file permissions are set to allow anyone to modify those files.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9015.html | vendor advisory |