Junglewise Threat Intelligence

CVE-2026-0432: AMD Chipset Driver privilege escalation via incorrect directory permissions

CVE-2026-0432 · Severity: info · CVSS 8.5 · Published 2026-05-15

Vendors: Amd.

Executive brief

A security vulnerability exists in the installation software for AMD chipset drivers, which are essential components that manage communication between a computer's processor and its hardware. Due to incorrect folder permissions, a user with low-level access to a system could replace legitimate driver files with malicious ones. This could allow an attacker to gain full administrative control over the computer, potentially leading to data theft or complete system takeover.

Technical details

A privilege escalation vulnerability exists in the AMD chipset driver installation directory due to incorrect default permissions (CWE-276). The flaw allows a local attacker with low privileges to modify or replace files within the installation path. By planting a malicious binary or DLL that is subsequently executed by a high-privileged process or service, the attacker can achieve arbitrary code execution with elevated system rights. The attack requires local access but no user interaction. AMD has acknowledged the issue in security bulletins AMD-SB-3047 and AMD-SB-4015.

Affected products

  • AMD Chipset Driver

Timeline

  • 2026-05-15: disclosed: NVD publication date

References