CVE-2024-21938: AMD Management Plugin For Sccm

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Affected products

  • AMD Management Plugin For Sccm: before 7.0.0.1318 (fixed in 7.0.0.1318)

Published 2024-11-12. Last modified 2026-06-17.