CVE-2023-20564 is a vulnerability in AMD Ryzen Master where insufficient validation of the IOCTL input buffer allows a privileged attacker to perform unauthorized memory reads and writes. This flaw can be exploited to achieve arbitrary kernel code execution or leak sensitive information from kernel memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2023-20564, a high-severity vulnerability in the AMD Ryzen Master Driver for Windows. The vulnerability allows unprivileged users to read and write arbitrary physical memory via IOCTLs exposed by the driver (0x81112F08 for read, 0x81112F0C for write), due to insufficient validation of user-supplied addresses and sizes. The repository contains two files: a detailed README.md explaining the vulnerability, exploitation steps, and mitigation, and poc.cpp, the main exploit code. The C++ code manages the installation and removal of the vulnerable driver, opens a handle to the device (\\.\AMDRyzenMasterDriverV17), and issues IOCTLs to perform physical memory read and write operations. The exploit demonstrates reading, writing, and verifying memory at arbitrary physical addresses, and can be used as a basis for privilege escalation or further kernel exploitation. The exploit is local (requires code execution on the target system with administrator privileges) and targets Windows 10/11 systems with the vulnerable driver installed. No network endpoints are involved; the main fingerprintable endpoints are the device interface and the driver file path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.