Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-21937


Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.


Published

2024-11-12T18:15:17.863

Last Modified

2024-11-27T16:20:37.073

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-276
  • Type: Primary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application amd radeon_software < 24.6.1 Yes
Application amd radeon_software < 24.7.1 Yes
Application amd radeon_software < 24.q2 Yes
Application amd radeon_software_for_hip < 24.10.16 Yes

References