« Volver al listado

CVE-2020-12897

Estado: ModificadaMedia (5.5)—

Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-12897",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@amd.com",
      "affectedData": [
        {
          "vendor": "AMD",
          "product": "AMD Radeon Software",
          "versions": [
            {
              "status": "affected",
              "version": "Radeon Software",
              "lessThan": "21.3.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "Radeon Pro Software for Enterprise",
              "lessThan": "21.Q2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-15T16:15:09.130",
  "references": [
    {
      "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1000",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@amd.com"
    },
    {
      "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1000",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass."
    },
    {
      "lang": "es",
      "value": "Una divulgación de la Dirección de Pool del Kernel en AMD Graphics Driver para Windows 10 puede conllevar a una omisión de KASLR"
    }
  ],
  "lastModified": "2026-06-17T02:52:30.523",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:amd:radeon_software:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3017A2C8-6079-4639-952E-E895FB6CB9A2",
              "versionEndExcluding": "21.3.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "21540673-614A-4D40-8BD7-3F07723803B0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@amd.com"
}