Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97c7-jg3h-5vf5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

EPSS

Процентиль: 16%
0.0005
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.8
nvd
больше 8 лет назад

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

fstec
около 9 лет назад

Уязвимость микропрограммного обеспечения, использующего код UEFI (BIOS), связанная с некорректным управлением генерацией кода, позволяющая нарушителю обходить системы защиты Device Guard и Hyper-V

EPSS

Процентиль: 16%
0.0005
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-94