Executive brief
A security vulnerability has been identified in the AMD Cleanup Utility, a tool used to remove previously installed AMD driver files and registry entries. An attacker with local access to a computer could exploit this flaw to gain higher-level system permissions. If successful, this could allow the attacker to run unauthorized programs with full administrative control, potentially compromising the entire device.
Technical details
A DLL hijacking vulnerability exists in the AMD Cleanup Utility due to insecure library loading practices. A local attacker with low privileges can place a malicious DLL file in a specific directory where the utility searches for dependencies. When the utility is executed by a user, it may load the malicious DLL instead of the legitimate one, leading to arbitrary code execution with the elevated privileges of the utility. This vulnerability requires local access and some level of user interaction to trigger the execution of the cleanup tool. AMD has addressed this issue in updated versions of the utility.
Affected products
- AMD Cleanup Utility
Timeline
- 2026-05-15: disclosed
- 2026-05-15: advisory