Impact
This vulnerability is a DLL hijacking flaw in the AMD Ryzen Master installation that enables a local user with sufficient privileges to place a malicious DLL in the firmware’s default load path. By doing so, the attacker can gain elevated privileges and execute arbitrary code with the same permissions as the Ryzen Master process. The weakness is cataloged as CWE‑427, indicating path‐related tampering.
Affected Systems
The risky components are AMD Ryzen Master for all processor families, the AMD Ryzen Master product designed for the Ryzen 3000 Series processors, and the AMD Ryzen Master SDK. No specific version information is available.
Risk and Exploitability
The CVSS score of 7 reflects a significant chance of privilege escalation, while the EPSS value of less than 1% indicates that exploitation is considered unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers need local executable access to the system in order to place the malicious DLL; thus it is a local‑user attack vector with moderate likelihood of success but potentially severe impact if successful.
OpenCVE Enrichment