CVE-2024-21925: Input Validation
Published Feb 11, 2025
·Updated
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.
Event History
Feb 11, 2025
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Apr 8, 2025
News Published
via The Register·11:43 PM
News Published
via The Register·11:47 PM
Apr 12, 2025
Known Exploited
11:50 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-21925?
CVE-2024-21925 has a high severity rating of 8.2 on the CVSS scale.
2
What are the potential impacts of CVE-2024-21925?
CVE-2024-21925 can lead to arbitrary code execution due to improper input validation in the AmdPspP2CmboxV2 driver.
3
Who is at risk from CVE-2024-21925?
Privileged attackers can exploit CVE-2024-21925 to overwrite SMRAM, making systems vulnerable.
4
How do I fix CVE-2024-21925?
Applying the latest security updates released by AMD will help mitigate the risks associated with CVE-2024-21925.
5
Is CVE-2024-21925 actively being exploited?
Yes, CVE-2024-21925 is flagged as exploited and was included in the Known Exploited Vulnerabilities List.