Cyber Posture

CVE-2024-46974

High

Published: 31 January 2025

Published
31 January 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0009 24.9th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-46974 is a high-severity Incorrect Privilege Assignment (CWE-266) vulnerability in Imaginationtech (inferred from references). Its CVSS base score is 7.8 (High).

Operationally, ranked at the 24.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-6 (Least Privilege) and SC-4 (Information in Shared System Resources).

Threat & Defense at a Glance

What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly mitigates the CVE by requiring timely identification, reporting, and patching of the vulnerable Imagination Technologies GPU driver.

prevent

Enforces least privilege to prevent non-privileged user software from conducting improper read/write operations on critical DMA buffers.

prevent

Protects information in shared system resources like DMA buffers from unauthorized access and transfer by low-privileged users.

NVD Description

Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.

Deeper analysisAI

CVE-2024-46974 affects the Imagination Technologies GPU driver, where software installed and run as a non-privileged user can conduct improper read/write operations on imported/exported DMA buffers. This vulnerability, published on 2025-01-31, is linked to CWE-266 (Incorrect Privilege Assignment for Critical Resource) and CWE-274 (Improper Handling of Insufficient Privileges or Quota). It carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to significant impacts on confidentiality, integrity, and availability.

A local attacker with low privileges can exploit this issue through low-complexity means without requiring user interaction. Exploitation allows improper access to DMA buffers, potentially enabling arbitrary read/write operations that compromise system security, data exposure, modification of critical resources, or denial of service.

Imagination Technologies has issued an advisory detailing GPU driver vulnerabilities, including CVE-2024-46974, available at https://www.imaginationtech.com/gpu-driver-vulnerabilities/. Security practitioners should review this reference for specific patch information, mitigation steps, and affected driver versions.

Details

CWE(s)

Affected Products

Imaginationtech
inferred from references and description; NVD did not file a CPE for this CVE

CVEs Like This One

CVE-2024-13251Shared CWE-266
CVE-2026-27102Shared CWE-266
CVE-2024-12470Shared CWE-266
CVE-2025-69293Shared CWE-266
CVE-2024-32444Shared CWE-266
CVE-2026-25414Shared CWE-266
CVE-2026-22907Shared CWE-266
CVE-2025-20156Shared CWE-274
CVE-2026-32520Shared CWE-266
CVE-2025-31643Shared CWE-266

References