CVE-2024-21924

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Feb 11, 2025
CWE ID 250

Summary

CVE-2024-21924 is a critical vulnerability affecting the AmdPlatformRasSspSmm driver. This issue involves a SMM callout vulnerability that can be exploited by a ring 0 attacker. By manipulating boot services handlers, an attacker could gain the ability to execute arbitrary code, potentially leading to significant system compromise. This vulnerability poses a serious threat and requires immediate attention from system administrators and hardware vendors.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share