EXPOSURES › CVE-2021-28664
CVE-2021-28664
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unspecified vulnerability in the Arm Mali GPU kernel driver allowed non-privileged users to gain root access, corrupt memory, and modify other processes.
The Arm Mali GPU kernel driver contained a flaw enabling privilege escalation and root compromise, which was actively exploited in the wild. DIB organizations must ensure GPU drivers are patched to prevent attackers from gaining system-level control through hardware components.
Shame score — The vulnerability was actively exploited in the wild and allowed full system compromise, indicating a severe and avoidable failure in hardware security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
"Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes."
"CISA urges immediate SharePoint hardening as exploits mount"
"Vendors List All Vendor TOP 100 Vendors with CVE"
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution"
"CISA sounds alarm over trio of exploited SharePoint flaws"
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."