ZeroHour

CVE-2022-26860

CVSS 3.1
7.8 high
EPSS
<1%p9
Published
()
Modified
Description

Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM.

Vendors
dell
Products
alienware m15 r6 firmware, chengming 3980 firmware, chengming 3988 firmware, chengming 3990 firmware, chengming 3991 firmware, g15 5510 firmware, g15 5511 firmware, g3 15 3590 firmware, g3 3500 firmware, g3 3579 firmware, g5 15 5587 firmware, g5 15 5590 firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.