CVE-2024-21937

Severity
7.8HIGH
EPSS
0.1%
top 72.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages4 packages

NVDamd/radeon_software< 24.6.1+3
CVEListV5amd/amd_software:_pro_edition< 24.10.16+1
CVEListV5amd/amd_software:_adrenalin_edition< 24.6.1 (24.10.21.01)

🔴Vulnerability Details

2
CVEList
CVE-2024-21937: Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting2024-11-12
GHSA
GHSA-cmh5-78pc-x57w: Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting2024-11-12
CVE-2024-21937 (HIGH CVSS 7.8) | Incorrect default permissions in th | cvebase.io