Junglewise Threat Intelligence

CVE-2024-36334: AMD Radeon RGB tool improper signature verification

CVE-2024-36334 · Severity: info · CVSS 7 · Published 2026-05-15

Vendors: Amd.

Executive brief

The AMD Radeon RGB tool, used for managing lighting on graphics cards, contains a security flaw in how it verifies software signatures. An attacker with local access to a computer could place a malicious file in the application's folder, which the tool would then run with high-level administrative permissions. This could allow an attacker to take full control of the system, potentially leading to data theft or permanent system compromise.

Technical details

A vulnerability classified as Improper Verification of Cryptographic Signature (CWE-347) exists in the AMD Radeon RGB tool. The application fails to correctly validate the authenticity of files within its installation directory before execution. A local attacker with low privileges can exploit this by placing a specially crafted malicious file in the directory. If a user interacts with the tool, the malicious code is executed with elevated privileges, leading to a full compromise of the host system. AMD has addressed this in security bulletin AMD-SB-6027.

Affected products

  • AMD Radeon RGB tool

Timeline

  • 2026-05-15: disclosed: Initial disclosure by AMD and NVD publication.
  • 2026-05-15: advisory: AMD Security Bulletin AMD-SB-6027 released.

References