PT-2024-11955 · Smm+1 · Smm+1

Published

2024-08-13

·

Updated

2025-08-13

·

CVE-2023-20578

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SMM (affected versions not specified)
Description A TOCTOU (Time-Of-Check-Time-Of-Use) issue in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer, potentially resulting in arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2025-09860
CVE-2023-20578

Affected Products

Red Os
Smm