CVE-2024-21947
CVE-2024-21947
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at the SMM level.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
AMD · AMD Athlon™ 3000 Series Desktop Processors with Radeon™ GraphicsAMD · AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 3000 Series Desktop ProcessorsAMD · AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 4000 Series Desktop ProcessorsAMD · AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 5000 Series Desktop ProcessorsAMD · AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 6000 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7000 Series Desktop ProcessorsAMD · AMD Ryzen™ 7020 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7035 Series Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ GraphicsAMD · AMD Ryzen™ 8000 Series Desktop ProcessorsAMD · AMD Ryzen™ Embedded 5000 Series ProcessorsAMD · AMD Ryzen™ Embedded R1000 Series ProcessorsAMD · AMD Ryzen™ Embedded R2000 Series ProcessorsAMD · AMD Ryzen™ Embedded V1000 Series ProcessorsAMD · AMD Ryzen™ Embedded V2000 Series ProcessorsAMD · AMD Ryzen™ Embedded V3000 Series ProcessorsAMD · AMD Ryzen™ Threadripper™ 3000 ProcessorsAMD · AMD Ryzen™ Threadripper™ PRO 3000 WX-Series ProcessorsAMD · AMD Ryzen™ Threadripper™ PRO 5000 WX-Series ProcessorsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →