SMM Callout Vulnerability in AmdCpmDisplayFeatureSMM Driver by AMD
CVE-2024-0179
Key Information:
- Vendor
- Amd
- Status
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2024-0179?
CVE-2024-0179 is a notable vulnerability in the AmdCpmDisplayFeatureSMM driver developed by AMD. This driver is integral to the operation of certain AMD hardware components, managing display features at the system management mode (SMM) level. The vulnerability allows locally authenticated attackers to overwrite system management RAM (SMRAM), which can lead to arbitrary code execution. Such an exploit could undermine the integrity of systems using AMD hardware, enabling attackers to impact system functionality and security.
Technical Details
CVE-2024-0179 specifically targets the SMM callout mechanism within the AmdCpmDisplayFeatureSMM driver. By exploiting this vulnerability, a malicious user who has gained local access to the system might manipulate SMRAM contents. This could allow for the execution of arbitrary code, presenting a critical threat to the stability and reliability of systems relying on this driver.
Potential Impact of CVE-2024-0179
-
Arbitrary Code Execution: Exploitation of this vulnerability could lead to unauthorized code execution within the highest privilege level of the system, enabling attackers to perform malicious activities without restrictions.
-
System Compromise: Successful exploitation may allow attackers to take complete control of the affected systems, jeopardizing confidential data and potentially facilitating further attacks within the network.
-
Operational Disruption: The ability to manipulate essential display features and codes can cause significant disruptions in operational environments, resulting in service outages or instability for organizations relying on AMD hardware systems.
Affected Version(s)
AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics ComboAM4PI 1.0.0.C
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics PicassoPI-FP5 1.0.1.2a
AMD Ryzen™ 3000 Series Desktop Processors ComboAM4PI 1.0.0.C
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved