Uprof
Vendor:
First CVE: Aug 13, 2024 · Active for 1 year
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Uprof over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2024
23 months ago
Most Recent CVE
Jun 9, 2026
45 days ago
CVE Severity & Scoring
Uprof11 CVEs
73%
27%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (81.8%)
Unknown0 (0.0%)
Required2 (18.2%)
Privileges Required
Low10 (90.9%)
High0 (0.0%)
None1 (9.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0466MEDIUM Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of servi | Jun 9, 2026 | 5.5 | 25 | NO | NO |
CVE-2026-28237MEDIUM Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability. | Jun 9, 2026 | 5.5 | 24 | NO | NO |
CVE-2025-48510HIGH Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability. | Nov 24, 2025 | 7.1 | 23 | NO | NO |
CVE-2023-31349HIGH Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | Aug 13, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-31348HIGH A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | Aug 13, 2024 | 7.8 | 22 | NO | NO |
CVE-2025-29933MEDIUM Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service | Nov 24, 2025 | 5.5 | 21 | NO | NO |
CVE-2025-48511MEDIUM Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service. | Nov 24, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-48502MEDIUM Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service. | Nov 21, 2025 | 5.5 | 20 | NO | NO |
CVE-2024-36340MEDIUM A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure | May 13, 2025 | 6.6 | 18 | NO | NO |
CVE-2023-31341MEDIUM Insufficient
validation of the Input Output Control (IOCTL) input buffer in AMD μProf may
allow an authenticated attacker to cause an out-of-bounds write, potentially
causing a Win | Aug 13, 2024 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Uprof
Top CWEs
Versions
No cataloged versions.