PT-2021-11218 · Dell · Dell Inspiron 5675 Bios

Yngweijw

·

Published

2021-01-08

·

Updated

2021-01-12

·

CVE-2020-26186

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Dell Inspiron 5675 BIOS versions prior to 1.4.1
Description: The issue allows a local attacker with access to system memory to exploit a UEFI BIOS RuntimeServices overwrite vulnerability. This can be done by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM).
Recommendations: For Dell Inspiron 5675 BIOS versions prior to 1.4.1, update the BIOS to version 1.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to system memory to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26186

Affected Products

Dell Inspiron 5675 Bios