Lucene search

K
cveAMDCVE-2020-12964
HistoryNov 15, 2021 - 3:15 p.m.

CVE-2020-12964

2021-11-1515:15:06
AMD
web.nvd.nist.gov
44
cve-2020-12964
amd radeon
kernel mode driver
privilege escalation
denial of service
windows bugcheck

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

12.6%

A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information.

Affected configurations

Nvd
Node
amdradeon_softwareRange<20.7.1
VendorProductVersionCPE
amdradeon_software*cpe:2.3:a:amd:radeon_software:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "AMD Radeon Software",
    "vendor": "AMD",
    "versions": [
      {
        "lessThan": "20.7.1",
        "status": "affected",
        "version": "Radeon Software",
        "versionType": "custom"
      },
      {
        "lessThan": "21.Q2",
        "status": "affected",
        "version": "Radeon Pro Software for Enterprise",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2020-12964