CVE-2024-36333
high
CVSS v3
7.8
CVSS v4 NEW
7.0
VIR risk
7.8
Description
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
Predictions
Exploit likelihood
75%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| amd | radeon_software | {"endExcluding":"26.q1"} | 26.q1 |
| amd | cleanup_utility | 25.20.00.00 | |
| amd | radeon_pro_vii | - | |
| amd | radeon_software | {"endExcluding":"25.q3.1"} | 25.q3.1 |
| amd | radeon_pro_w5500 | - | |
| amd | radeon_pro_w5500x | - | |
| amd | radeon_pro_w5700 | - | |
| amd | radeon_pro_w5700x | - | |
| amd | radeon_pro_w6300 | - | |
| amd | radeon_pro_w6300m | - | |
| amd | radeon_pro_w6400 | - | |
| amd | radeon_pro_w6500m | - | |
| amd | radeon_pro_w6600 | - | |
| amd | radeon_pro_w6600m | - | |
| amd | radeon_pro_w6600x | - | |
| amd | radeon_pro_w6800 | - | |
| amd | radeon_pro_w6800x | - | |
| amd | radeon_pro_w6800x_duo | - | |
| amd | radeon_pro_w6900x | - | |
References
CWEs
CWE-427
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.