Home

Description

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

PUBLISHED Reserved 2024-01-03 | Published 2024-11-12 | Updated 2024-11-14 | Assigner AMD




HIGH: 7.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-276 Incorrect Default Permissions

Product status

Default status
unaffected

Any version before 24.10.16
affected

Any version before 24.Q2 (24.10.20)
affected

Default status
unaffected

Any version before 24.6.1 (24.10.21.01)
affected

Default status
unaffected

Any version before 24.7.1
affected

References

www.amd.com/...es/product-security/bulletin/amd-sb-6015.html

cve.org (CVE-2024-21937)

nvd.nist.gov (CVE-2024-21937)

Download JSON