Skip to content
COOEY

EXPOSURES › CVE-2021-28664

CVE-2021-28664

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-28664 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

An unspecified vulnerability in the Arm Mali GPU kernel driver allowed non-privileged users to gain root access, corrupt memory, and modify other processes.

The Arm Mali GPU kernel driver contained a flaw enabling privilege escalation and root compromise, which was actively exploited in the wild. DIB organizations must ensure GPU drivers are patched to prevent attackers from gaining system-level control through hardware components.

Shame score — The vulnerability was actively exploited in the wild and allowed full system compromise, indicating a severe and avoidable failure in hardware security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread concern and active exploitation highlighted the severity of the vulnerability.
cvefeed.io ↗ severe-fallout -0.70
Highlights active exploitation, indicating a serious issue.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
cooey ↗ severe-fallout -0.60
Neutral description of the vulnerability.
"Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes."
www.csoonline.com ↗ severe-fallout +0.00
Focuses on SharePoint vulnerabilities, not Arm.
"CISA urges immediate SharePoint hardening as exploits mount"
www.cvefind.com ↗ severe-fallout +0.00
Provides context and lists Arm among vendors.
"Vendors List All Vendor TOP 100 Vendors with CVE"
cybersecuritynews.com ↗ severe-fallout +0.00
Focuses on SharePoint vulnerabilities, not Arm.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution"
The Register ↗ severe-fallout +0.00
Focuses on SharePoint vulnerabilities, not Arm.
"CISA sounds alarm over trio of exploited SharePoint flaws"
cvedb.shodan.io ↗ severe-fallout +0.00
Provides API information, no sentiment.
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.