CVE Database
/

CVE-2024-21924

Back to search

CVE-2024-21924

Published: Feb 11, 2025

Modified: Feb 11, 2025

PUBLISHED

CVSS v3.1

8.2

HIGH

Description

SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.

VendorProductVersions

AMD

AMD EPYC™ 7002 Processors

unaffected
Rome PI 1.0.0.K

AMD

AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors

unaffected
ChagallWSPI-sWRX8 1.0.0.9

AMD

AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors

unaffected
CastlePeakWSPI-sWRX8 1.0.0.E

AMD

AMD Ryzen™ Threadripper™ PRO 5000WX- Series Desktop Processors

unaffected
ChagallWSPI-sWRX8 1.0.0.9

AMD

AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors

unaffected
StormPeakPI-SP6 1.1.0.0h

AMD

AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors

unaffected
StormPeakPI-SP6 1.0.0.1j

AMD

AMD EPYC™ Embedded 7002 Processors

unaffected
EmbRomePI-SP3 1.0.0.D

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now