« Back to list

AMD

AMD Uprof: vulnerabilities and CVEs

AMD Uprof has 7 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months1
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-61969High (7)0.14%—Feb 11, 2026
Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2023-20562High (7.8)0.98%—Aug 8, 2023
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
CVE-2023-20561Medium (5.5)0.27%—Aug 8, 2023
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service.
CVE-2023-20556Medium (5.5)0.27%—Aug 8, 2023
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service.
CVE-2022-27674High (7.5)0.73%—Nov 9, 2022
Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.
CVE-2022-23831High (7.5)0.70%—Nov 9, 2022
Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.
CVE-2021-26334Critical (9.9)1.2%—Dec 1, 2021
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation1
  2. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by AMD