CVE-2024-36334 PUBLISHED

Assigner: AMD
Reserved: 23.05.2024 Published: 15.05.2026 Updated: 15.05.2026

Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arbitrary code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor AMD
Product AMD Radeon™ RX 7000 Series Graphics Products
Versions Default: affected
  • Version amd_rx_7900_xtx_rgb_led_20241008.exe “AMD Radeon RX 7900 XTX RGB Tool” available at https://www.amd.com/en/support/downloads/drivers.html/graphics/radeon-rx/radeon-rx-7000-series/amd-radeon-rx-7900-xtx.html is unaffected

Credits

  • Reported through AMD Bug Bounty Program

References

Problem Types

  • CWE-347 Improper Verification of Cryptographic Signature CWE