CVE-2020-12891

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amd:radeon_pro_software:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:amd:radeon_software:*:*:*:*:*:*:*:*

History

09 Feb 2022, 14:11

Type Values Removed Values Added
First Time Amd
Amd radeon Software
Amd radeon Pro Software
CVSS v2 : unknown
v3 : unknown
v2 : 4.4
v3 : 7.8
CPE cpe:2.3:a:amd:radeon_pro_software:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:amd:radeon_software:*:*:*:*:*:*:*:*
CWE CWE-427
References (MISC) https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1000 - (MISC) https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1000 - Vendor Advisory

04 Feb 2022, 23:28

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-04 23:15

Updated : 2023-12-10 14:09


NVD link : CVE-2020-12891

Mitre link : CVE-2020-12891

CVE.ORG link : CVE-2020-12891


JSON object : View

Products Affected

amd

  • radeon_software
  • radeon_pro_software
CWE
CWE-427

Uncontrolled Search Path Element