CVE-2023-20598
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.
Early warning: exploitation observed
- Exploitation observed since Oct 8, 2025
- Not yet in the official CISA catalogue
- First attack observed 721 days after disclosure
Source: VulnCheck KEV · Sep 24, 2026 Oct 8, 2025
CVSS score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-269
Vendorsamd
Affected products
| Vendors | Product | Versions |
|---|---|---|
| amd | radeon software | < 23.9.2 |
| amd | radeon rx 5300 | - |
| amd | radeon rx 5300 xt | - |
| amd | radeon rx 5300m | - |
| amd | radeon rx 5500 | - |
| amd | radeon rx 5500 xt | - |
| amd | radeon rx 5500m | - |
| amd | radeon rx 5600 | - |
| amd | radeon rx 5600 xt | - |
| amd | radeon rx 5600m | - |
| amd | radeon rx 5700 | - |
| amd | radeon rx 5700 xt | - |
| amd | radeon rx 5700m | - |
| amd | radeon rx 6300m | - |
| amd | radeon rx 6400 | - |
| amd | radeon rx 6450m | - |
| amd | radeon rx 6500 xt | - |
| amd | radeon rx 6500m | - |
| amd | radeon rx 6550m | - |
| amd | radeon rx 6550s | - |
| amd | radeon rx 6600 | - |
| amd | radeon rx 6600 xt | - |
| amd | radeon rx 6600m | - |
| amd | radeon rx 6600s | - |
| amd | radeon rx 6650 xt | - |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
