ZeroHour

CVE-2023-28075

CVSS 3.1
6.3 medium
EPSS
<1%p8
Published
()
Modified
Description

Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.

Vendors
dell
Products
alienware m15 r7 firmware, alienware m16 firmware, alienware m18 firmware, chengming 3900 firmware, chengming 3901 firmware, chengming 3910 firmware, chengming 3911 firmware, chengming 3980 firmware, chengming 3990 firmware, chengming 3991 firmware, g15 5520 firmware, g16 7620 firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.