CVE-2024-21937

HIGH

AMD Radeon Software < 24.6.1, < 24.7.1, < 24.q2 & HIP < 24.10.16 - Privilege Escalation via Default Permissions

Title source: llm
STIX 2.1

Description

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0010
EPSS Percentile 27.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (4)
amd/radeon_software < 24.6.1
amd/radeon_software < 24.7.1
amd/radeon_software < 24.q2
amd/radeon_software_for_hip < 24.10.16
Published Nov 12, 2024
Tracked Since Feb 18, 2026