CVE-2023-20568: AMD Radeon Pro Vega 56 Firmware

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

Affected products

  • AMD Radeon Pro Vega 56 Firmware: affected versions not specified
  • AMD Radeon Pro Vega 64 Firmware: affected versions not specified
  • AMD Radeon Rx Vega 56 Firmware: affected versions not specified
  • AMD Radeon Rx Vega 64 Firmware: affected versions not specified
  • AMD Radeon Software: before 23.7.1 (fixed in 23.7.1); before 23.q3 (fixed in 23.q3)
  • Intel Radeon Rx Vega M Firmware: before 23.10.01.46 (fixed in 23.10.01.46)

Published 2023-11-14. Last modified 2026-06-17.