cbcvebase.
CVE-2024-21937
published 2024-11-12

CVE-2024-21937: Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.6th percentile
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Affected

8 ranges
VendorProductVersion rangeFixed in
amdamd_software_adrenalin_edition< 24.6.1 (24.10.21.01)24.6.1 (24.10.21.01)
amdamd_software_cloud_edition< 24.7.124.7.1
amdamd_software_pro_edition< 24.10.1624.10.16
amdamd_software_pro_edition< 24.Q2 (24.10.20)24.Q2 (24.10.20)
amdradeon_software< 24.6.124.6.1
amdradeon_software< 24.7.124.7.1
amdradeon_software< 24.q224.q2
amdradeon_software_for_hip< 24.10.1624.10.16
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.