Executive brief
A security vulnerability exists in certain optional AMD software tools that could allow a person with physical or local access to a computer to take control of the system. By placing a malicious file in a specific location, an attacker can trick the software into running unauthorized code. This could lead to a full system compromise, allowing the attacker to view sensitive data or disrupt operations.
Technical details
A DLL hijacking vulnerability (CWE-427: Uncontrolled Search Path Element) exists in certain AMD optional tools due to unsafe OpenSSL initialization. A local attacker with low privileges can exploit this by placing a malicious DLL in the application's search path. If a user subsequently runs the affected tool, the application may load the malicious library instead of the intended one, leading to arbitrary code execution with the privileges of the application. The vulnerability requires local access and some level of user interaction to trigger the execution of the affected tool.
Affected products
- AMD Optional Tools
Timeline
- 2026-05-14: disclosed: Initial disclosure by AMD
- 2026-05-14: advisory: NVD record published