PT-2025-36390 · Dimm · Dimm

Published

2025-09-06

·

Updated

2025-09-23

·

CVE-2024-36354

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Affected versions not specified
Description Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation, potentially resulting in arbitrary code execution at the SMM level.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-36354

Affected Products

Dimm