CVE-2024-36333
high
CVSS v3
7.8
CVSS v2
—
VIR risk
7.8
Description
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@amd.com — https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| amd | radeon_software | {"endExcluding":"26.q1"} | 26.q1 |
| amd | cleanup_utility | 25.20.00.00 | |
References
CWEs
CWE-427
Verify integrity in audit chain (admin only). AS-IS.