Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcw6-g65p-gcjw

Опубликовано: 08 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.2
redhat
больше 2 лет назад

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.

CVSS3: 7.8
nvd
больше 2 лет назад

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость компонент CpmDisplayFeatureSmm микропрограммного обеспечения процессоров AMD, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-787