PT-2023-8776 · Dell · Dell Precision Bios+1

Published

2023-05-22

·

Updated

2023-05-30

·

CVE-2023-25537

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerEdge 14G server BIOS versions prior to 2.18.1 Dell Precision BIOS versions prior to 2.18.2
Description The issue is related to an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability, leading to exposure of some SMRAM stack/data/code in System Management Mode, which could result in arbitrary code execution or escalation of privilege.
Recommendations For Dell PowerEdge 14G server BIOS versions prior to 2.18.1, update to version 2.18.1 or later to resolve the issue. For Dell Precision BIOS versions prior to 2.18.2, update to version 2.18.2 or later to resolve the issue.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-01875
CVE-2023-25537

Affected Products

Dell Poweredge 14G Server Bios
Dell Precision Bios