CVEFinder.io

CVE-2024-21937

âš ī¸ high
🔍 Scan for this CVE
Summary

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

CVSS Score
7.3
High
EPSS Score
0.1
Exploit Probability
Published Date
2024-11-12
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 55.5% of all 330,193 vulnerabilities in our database.

#147,095
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Nov 14, 2024
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2024-11-27
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 4

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2024-36333 âš ī¸ high 7.8 0.0 A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti... 2026-05-15
CVE-2023-20548 âš ī¸ high 7.8 0.0 A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt... 2026-02-11
CVE-2023-31324 âš ī¸ high 7.8 0.0 A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify ... 2026-02-11
CVE-2021-26367 đŸ”ļ medium 5.7 0.0 A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an a... 2024-08-13
CVE-2023-20510 đŸ”ļ medium 4.7 0.0 An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to ... 2024-08-13
CVE-2023-31307 â„šī¸ low 2.3 0.1 Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-o... 2024-08-13
These CVEs affect the same products