CVE-2024-21937: AMD Radeon Software
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
Affected products
- AMD Radeon Software: before 24.6.1 (fixed in 24.6.1); before 24.7.1 (fixed in 24.7.1); before 24.q2 (fixed in 24.q2)
- AMD Radeon Software For Hip: before 24.10.16 (fixed in 24.10.16)
Published 2024-11-12. Last modified 2026-06-17.