CVE-2023-20556: AMD Uprof
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.
Affected products
- AMD AMD Uprof: before 4.1.396 (fixed in 4.1.396); before 4.1-424 (fixed in 4.1-424)
Published 2023-08-08. Last modified 2026-06-17.