CVE-2022-34403
—CVSS 3.1
8.8 high
EPSS
<1%p6
Published
()
Modified
Description
Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM.
- Vendors
- dell
- Products
- alienware m15 r6 firmware, alienware m15 r7 firmware, alienware m15 ryzen edition r5 firmware, alienware m17 r5 amd firmware, g15 5510 firmware, g15 5511 firmware, g15 5515 firmware, g15 5525 firmware, g5 se 5505 firmware, inspiron 14 5410 2-in-1 firmware, inspiron 15 3511 firmware, inspiron 3195 2-in-1 firmware
- Weakness
- CWE-121, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.