CVE-2024-21939: AMD Cloud Manageability Service

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Affected products

  • AMD Cloud Manageability Service: before 2.0.0.232 (fixed in 2.0.0.232)

Published 2024-11-12. Last modified 2026-06-17.