Vulnerability Description
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Amd Uprof | < 3.4.494 |
| Microsoft | Windows | - |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1016MitigationVendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1016MitigationVendor Advisory
FAQ
What is CVE-2021-26334?
CVE-2021-26334 is a vulnerability with a CVSS score of 9.9 (CRITICAL). The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged use...
How severe is CVE-2021-26334?
CVE-2021-26334 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-26334?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Amd Uprof, Microsoft Windows, Linux Linux Kernel.