CVE-2023-20578 - CERT CVE
ID CVE-2023-20578
Sažetak A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
Reference
CVSS
Base: 7.5
Impact: 6.0
Exploitability:0.8
Pristup
VektorSloženostAutentikacija
LOCAL HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Zadnje važnije ažuriranje 18-03-2025 - 20:15
Objavljeno 13-08-2024 - 17:15