Vulnerability CVE-2023-28075


Published: 2023-08-16

Description:

Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.

Type:

CWE-367

(Time-of-check Time-of-use (TOCTOU) Race Condition)

 References:
https://www.dell.com/support/kbdoc/en-us/000212817/dsa-2023-152-security-update-for-a-dell-client-bios-vulnerability

Copyright 2024, cxsecurity.com

 

Back to Top