CVE-2024-0179
published 2025-02-11CVE-2024-0179: SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in…
PriorityP339high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.20%
10.2th percentile
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_ryzen_embedded_r2000 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pjg6-r723-9cv2: SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially result
ghsa_unreviewed·2025-02-11
CVE-2024-0179 [HIGH] CWE-20 GHSA-pjg6-r723-9cv2: SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially result
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
Red Hat
kernel: hw:amd: SMM callout vulnerability within the AmdCpmDisplayFeatureSMM
vendor_redhat·2025-02-11·CVSS 8.2
CVE-2024-0179 [HIGH] CWE-119 kernel: hw:amd: SMM callout vulnerability within the AmdCpmDisplayFeatureSMM
kernel: hw:amd: SMM callout vulnerability within the AmdCpmDisplayFeatureSMM
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
A flaw was found in the UEFI module's System Management Mode (SMM). SMM callout within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
Statement: These vulnerabilities can allow a ring 0 attacker to escalate their privileges,
potentially resulting in arbitrary code execution within SMM.
Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to p
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-11
Published