CVE-2024-21939
HIGHAMD Cloud Manageability Service < 2.0.0.232 - Privilege Escalation via Insecure Installation Directory Permissions
Title source: llmDescription
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
References (1)
Core 1
Core References
Scores
CVSS v3
7.3
EPSS
0.0010
EPSS Percentile
27.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (1)
amd/cloud_manageability_service
< 2.0.0.232
Published
Nov 12, 2024
Tracked Since
Feb 18, 2026