PT-2025-2941 · Unknown · Graphics Ddk

Published

2025-01-13

·

Updated

2025-01-31

·

CVE-2024-52936

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Graphics DDK version <= 24.2 RTM2
Description Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Recommendations For versions <= 24.2 RTM2, consider restricting access to the GPU Firmware until a patch is available. As a temporary workaround, disabling the ability of the kernel software to post commands to the GPU Firmware may help minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-52936

Affected Products

Graphics Ddk