CVE-2024-36324

8.8

AMD · Graphics Driver

Improper input validation in the AMD Graphics Driver allows for an out-of-bounds write via a crafted pointer, potentially leading to arbitrary code execution.

Executive summary

A critical vulnerability in AMD Graphics Drivers could allow a local attacker to achieve arbitrary code execution on affected systems.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) resulting from improper input validation. An attacker with local access and low privileges can supply a specially crafted pointer to the driver, which may result in arbitrary code execution with elevated system privileges.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational assets, as it allows attackers to bypass security controls, escalate privileges, or install malicious software. With a CVSS score of 8.8, this flaw is categorized as High severity, reflecting the significant risk of full system compromise if local access is achieved. Such an event could lead to unauthorized data exfiltration, persistent malware infection, or complete loss of system integrity.

Remediation

Immediate Action: Update the AMD Graphics Driver to version 25.6.1 (25.10.13.01) for Adrenalin Edition, or version 25.Q2 (25.10.10) for PRO Edition.

Proactive Monitoring: Monitor system logs for unusual driver crashes or unexpected process executions that might indicate an attempt to exploit memory corruption vulnerabilities.

Compensating Controls: Restrict local access to systems running these processors to authorized users only, and utilize endpoint detection and response tools to identify unauthorized privilege escalation attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant security risk for environments utilizing the affected AMD hardware. Administrators should prioritize the deployment of the specified driver updates to all workstations and servers within the production environment to mitigate this risk effectively.

More AMD CVEs

Sources

Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.