CVE-2020-12928 is a local privilege escalation vulnerability in a dynamically loaded AMD driver used by AMD Ryzen Master V15. The affected driver is identified in the provided content as AODDriver 2.1.5 and below, with related filenames including AMDRyzenMasterDriver.sys and AODDriver215.sys. According to the provided description, the flaw may allow any authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. The supplied content does not include the specific vulnerable IOCTL handler, function, or code path, so more granular root-cause detail is currently not available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Visual Studio C project for a local privilege escalation proof of concept targeting CVE-2020-12928 in AMD Ryzen Master / AMDRyzenMasterDriver.sys on Windows. The repo contains 10 files, but almost all are project metadata or build artifacts; the actual exploit logic is intended to reside in a single C source file, AMDRyzenExploit/AMDRyzenExploit/main.c, referenced by the .vcxproj. That source file is not included in the provided content, so the exact IOCTLs, device names, and kernel primitives cannot be extracted directly. Repository structure indicates a standard Visual Studio console application configured for Win32 and x64, with x64 debug artifacts present. The README explicitly labels it as 'LPE Exploit code' for CVE-2020-12928 and links to public writeups about exploiting the Ryzen Master driver. Build logs confirm compilation of main.c and show numerous type-casting and pointer warnings, which is consistent with low-level Windows kernel/driver exploit development. Based on the README and project naming, the exploit's main capability is local privilege escalation via a vulnerable signed AMD driver, likely by issuing crafted requests to the driver to obtain arbitrary kernel read/write or a similar primitive and then elevating the current process token. No network communication, C2, or remote targeting is evident from the repository contents. Because no payload customization or post-exploitation module is visible and the core source is missing from the provided archive, the most appropriate maturity assessment is POC rather than operational or weaponized.
This repository, 'EC_PRO-LAN', is a multi-component cheat/exploit framework targeting the AMD RyzenMaster driver vulnerability on Windows systems. It is designed to bypass anti-cheat protections (FACEIT, ESEA) for the game CS:GO by leveraging a vulnerable AMD RyzenMaster driver to read and manipulate game memory and simulate mouse input. The exploit consists of several components: - **client_windows**: Windows C++ client that connects to a server (typically running on the same or another LAN machine), reads game memory from the CS:GO process, and manipulates mouse input for aimbot functionality. It uses a configuration file (`config.cfg`) to specify server IP, aimbot keys, FOV, smoothness, and other cheat parameters. The client injects a DLL (`opengl32.dll`) into the AMD RyzenMaster directory to exploit the vulnerable driver. - **server**: C/C++ server component that runs on the target Windows machine, listens on TCP port 30609, and executes privileged memory operations via the AMD RyzenMaster driver. It uses a custom RC4-encrypted protocol for communication and function dispatch. - **client_android**: Android app (Java/C++ via JNI) that acts as a remote client, allowing control of the aimbot/cheat features over WiFi/LAN. The app provides a GUI for connecting to the server, adjusting aimbot parameters, and sending commands. The exploit requires specific hardware and software configuration (Windows 10 Enterprise 1607 LTSB, AMD Ryzen CPU, B350/B450 motherboard, Logitech GHUB). It targets the AMD RyzenMaster driver (notably version 1.3.0.0, but possibly others) to gain arbitrary kernel memory access, which is then used to read/write CS:GO process memory and bypass anti-cheat mechanisms. The communication between client and server is over TCP (default port 30609), and the system is designed for use within a trusted LAN environment. The repository includes both the exploit code and the infrastructure for remote control via Android or another PC. No detection-only scripts are present; this is a fully operational exploit/cheat framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.