PT-2021-20235 · Smm · Smm

Published

2021-10-01

·

Updated

2022-04-24

·

CVE-2021-33626

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SMM (System Management Mode) (affected versions not specified)
Description: A vulnerability exists in the SMM branch that registers a SWSMI handler, which does not sufficiently check or validate the allocated buffer pointer (QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and potentially lead to arbitrary code execution.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33626

Affected Products

Smm