« Volver al listado

CVE-2024-21979

Estado: AplazadaMedia (5.3)—

An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-21979",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-21979",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-23T18:58:00.311801Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@amd.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@amd.com",
      "affectedData": [
        {
          "vendor": "AMD",
          "product": "AMD Software: Adrenalin Edition ",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "12.1.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "AMD",
          "product": "AMD Software: PRO Edition",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "24.Q1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:amd:radeon_directx_11_driver_dll:*:*:*:*:*:*:*:*"
          ],
          "vendor": "amd",
          "product": "radeon_directx_11_driver_dll",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-23T17:15:46.877",
  "references": [
    {
      "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6012.html",
      "source": "psirt@amd.com"
    },
    {
      "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6012.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1847",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@amd.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nAn out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.\n\n"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de escritura fuera de los límites en el controlador de modo de usuario AMD Radeon™ para DirectX® 11 podría permitir que un atacante con acceso a un sombreador con formato incorrecto logre potencialmente la ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T07:10:29.037",
  "sourceIdentifier": "psirt@amd.com"
}