PT-2022-22158 · Dell · Dell Client Bios
Yngweijw
·
Published
2022-10-12
·
Updated
2022-10-13
·
CVE-2022-34391
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Client BIOS versions prior to the remediated version
Description
The issue is related to improper input validation, which could be exploited by a local authenticated malicious user. This exploitation could potentially lead to arbitrary code execution in SMRAM by using a System Management Interrupt (SMI).
Recommendations
For versions prior to the remediated version, update to the remediated version to resolve the issue. As a temporary workaround, consider restricting access to SMI handlers to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Client Bios