CVE-2023-31341: AMD Uprof

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.

Affected products

  • AMD Uprof: before 4.1.424 (fixed in 4.1.424); before 4.2.816 (fixed in 4.2.816); before 4.2.845 (fixed in 4.2.845)

Published 2024-08-13. Last modified 2026-06-17.