CVE-2023-20598 is an improper privilege management flaw in the AMD Radeon Graphics driver (NVD, CWE-269, CVSS 7.8 High, published 17 October 2023): an authenticated attacker can craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses, with potential arbitrary code execution.
The flaw became operationally significant in September 2026 when Ontinue reported that the Lunex malware-as-a-service loader uses the signed driver PDFWKRNL.sys as a bring-your-own-vulnerable-driver component. Rather than terminating endpoint security processes, the loader uses PDB-guided kernel callback zeroing to blind them while leaving them running, then deploys an information stealer that harvests credentials from seven Chromium-based browsers. Ontinue's testing found neither HVCI nor the current Microsoft Vulnerable Driver Blocklist blocks this specific driver variant from loading, even though its hash has been catalogued in the LOLDrivers project since March 2026 — see The Stealer Delivered Through Hacked Ukrainian Sites Is One Module Of A Sold Pla for the full chain.
| Attribute | Detail |
|---|---|
| CVE | CVE-2023-20598 |
| CVSS | 7.8 (High) |
| Vendor / product | AMD — Radeon Graphics driver (PDFWKRNL.sys) |
| Reported | 2023-10-17 |