PT-2022-21340 · Dell · Dell Bios

Yngweijw

·

Published

2022-10-12

·

Updated

2022-10-14

·

CVE-2022-32487

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell BIOS (affected versions not specified)
Description The issue is related to improper input validation in Dell BIOS, which can be exploited by a local authenticated malicious user. This exploitation can occur through the use of a System Management Interrupt (SMI) to achieve arbitrary code execution in System Management RAM (SMRAM).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-32487

Affected Products

Dell Bios