ZeroHour

CVE-2021-46772

CVSS 3.1
3.9 low
EPSS
<1%p8
Published
()
Modified
Description

Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure headers in SPI ROM causing an out of bounds memory read and write, potentially resulting in memory corruption or denial of service.

Weakness
CWE-125, CWE-787
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.