PT-2022-25307 · Unknown · S3Resume2Pei

Published

2022-09-20

·

Updated

2022-09-26

·

CVE-2022-40262

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions S3Resume2Pei (affected versions not specified)
Description A potential attacker can execute arbitrary code during the PEI phase, influencing subsequent boot stages. This can lead to bypassing mitigations, disclosure of physical memory contents, discovery of secrets from Virtual Machines (VMs), and bypassing memory isolation and confidential computing boundaries. An attacker can also build a payload to inject into the SMRAM memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-40262

Affected Products

S3Resume2Pei