CVE-2024-0179: Input Validation
Published Feb 11, 2025
·Updated
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
Affected Software
1 affected component
AMD AmdCpmDisplayFeatureSMM driver
Event History
Feb 11, 2025
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Apr 8, 2025
News Published
via The Register·11:43 PM
News Published
via The Register·11:47 PM
Apr 12, 2025
Known Exploited
11:50 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-0179?
The severity of CVE-2024-0179 is classified as high, with a CVSS score of 8.2.
2
What types of systems are affected by CVE-2024-0179?
CVE-2024-0179 affects systems running the AmdCpmDisplayFeatureSMM driver and is vulnerable to locally authenticated attacks.
3
How do I fix CVE-2024-0179?
To fix CVE-2024-0179, apply the latest security patches provided by the vendor for the affected driver.
4
What are the potential impacts of exploiting CVE-2024-0179?
Exploiting CVE-2024-0179 could allow attackers to overwrite SMRAM, leading to arbitrary code execution.
5
Is CVE-2024-0179 being actively exploited?
Yes, CVE-2024-0179 is flagged as exploited and is listed in the Known Exploited Vulnerabilities (KEV) catalog.