Executive brief
AMD Ryzen Master is a system utility that allows users to manage CPU and memory settings on AMD Ryzen processors. A DLL hijacking vulnerability in the installation process could allow a local attacker to execute arbitrary code with elevated privileges, potentially gaining full system control.
Technical details
This vulnerability is a DLL hijacking (also known as DLL preloading or binary planting) flaw in the AMD Ryzen Master installer. The installer or application fails to validate or securely load DLL files during execution, allowing an attacker with local user privileges to place a malicious DLL in a location where the application will load it instead of the legitimate library. Successful exploitation requires local system access and the ability to write to directories searched by the application. An attacker can execute arbitrary code in the context of the process running Ryzen Master, potentially with elevated privileges if the installer or service runs with SYSTEM or administrator rights. Patches or mitigations should be available through AMD security updates.
Affected products
- AMD Ryzen Master
Timeline
- 2026-08-11: disclosed