CVE-2021-26334

The AMDPowerProfiler.sys driver of AMD µProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:amd:amd_uprof:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:amd:amd_uprof:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:31

Type Values Removed Values Added
Summary The AMDPowerProfiler.sys driver of AMD ?Prof tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user. The AMDPowerProfiler.sys driver of AMD µProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.

26 Apr 2022, 15:34

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

03 Dec 2021, 19:20

Type Values Removed Values Added
References (MISC) https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1016 - (MISC) https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1016 - Mitigation, Vendor Advisory
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 9.9
CPE cpe:2.3:a:amd:amd_uprof:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

01 Dec 2021, 16:19

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-01 16:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-26334

Mitre link : CVE-2021-26334

CVE.ORG link : CVE-2021-26334


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

amd

  • amd_uprof
CWE
NVD-CWE-Other CWE-284

Improper Access Control