Micron's vulnerability footprint is concentrated in memory and storage products, particularly DDR4 SDRAM modules and solid-state drives from its Crucial brand, along with supporting firmware and management utilities. The observed weakness classes center on input-validation handling and issues requiring further classification, reflecting the firmware and driver-level exposure typical of embedded storage and memory components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Micron over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42114HIGH Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer | Nov 16, 2021 | 8.3 | 27 | NO | NO |
CVE-2021-41285HIGH Ballistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vulnerability is triggered by sending a specific IOCTL request t | Oct 4, 2021 | 7.8 | 26 | NO | NO |
CVE-2020-10255CRITICAL Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations against RowHammer attacks known as Target Row Refresh (TRR), ak | Mar 10, 2020 | 9.0 | 23 | NO | NO |
CVE-2018-12037MEDIUM An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial | Nov 20, 2018 | 4.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Micron.
Media articles that mention a CVE ID that affects a product developed by Micron — matched by CVE ID, not by vendor name.