ZeroHour

CVE-2022-34403

CVSS 3.1
8.8 high
EPSS
<1%p6
Published
()
Modified
Description

Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM.

Vendors
dell
Products
alienware m15 r6 firmware, alienware m15 r7 firmware, alienware m15 ryzen edition r5 firmware, alienware m17 r5 amd firmware, g15 5510 firmware, g15 5511 firmware, g15 5515 firmware, g15 5525 firmware, g5 se 5505 firmware, inspiron 14 5410 2-in-1 firmware, inspiron 15 3511 firmware, inspiron 3195 2-in-1 firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.