CVE-2023-20567: AMD Radeon Pro Vega 56 Firmware
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.
Affected products
- AMD Radeon Pro Vega 56 Firmware: affected versions not specified
- AMD Radeon Pro Vega 64 Firmware: affected versions not specified
- AMD Radeon Rx Vega 56 Firmware: affected versions not specified
- AMD Radeon Rx Vega 64 Firmware: affected versions not specified
- AMD Radeon Software: before 23.7.1 (fixed in 23.7.1); before 23.q3 (fixed in 23.q3)
- Intel Radeon Rx Vega M Firmware: before 23.10.01.46 (fixed in 23.10.01.46)
Published 2023-11-14. Last modified 2026-06-17.