Show filters
183 Total Results
Displaying 81-90 of 183
Sort by:
Attacker Value
Unknown
CVE-2022-4575
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
0
Attacker Value
Unknown
CVE-2023-4692
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
0
Attacker Value
Unknown
CVE-2023-30738
Disclosure Date: October 04, 2023 (last updated October 09, 2023)
An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.
0
Attacker Value
Unknown
CVE-2023-34195
Disclosure Date: September 18, 2023 (last updated February 25, 2025)
An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a runtime variable named GetImageProgress, and later uses this value as a function pointer. This variable is wiped out by the same module near the end of the function. By setting this UEFI variable from the OS to point into custom code, an attacker could achieve arbitrary code execution in the DXE phase, before several chipset locks are set.
0
Attacker Value
Unknown
CVE-2023-28538
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
0
Attacker Value
Unknown
CVE-2022-3744
Disclosure Date: August 23, 2023 (last updated February 25, 2025)
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
0
Attacker Value
Unknown
CVE-2023-27471
Disclosure Date: August 18, 2023 (last updated October 08, 2023)
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect and validate information contained in the 'MeSetup' UEFI variable. On some systems, this variable can be overwritten using operating system APIs. Exploitation of this vulnerability could potentially lead to denial of service for the platform.
0
Attacker Value
Unknown
CVE-2023-32453
Disclosure Date: August 16, 2023 (last updated February 25, 2025)
Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS administrator.
0
Attacker Value
Unknown
CVE-2023-39950
Disclosure Date: August 14, 2023 (last updated February 25, 2025)
efibootguard is a simple UEFI boot loader with support for safely switching between current and updated partition sets. Insufficient or missing validation and sanitization of input from untrustworthy bootloader environment files can cause crashes and probably also code injections into `bg_setenv`) or programs using `libebgenv`. This is triggered when the affected components try to modify a manipulated environment, in particular its user variables. Furthermore, `bg_printenv` may crash over invalid read accesses or report invalid results. Not affected by this issue is EFI Boot Guard's bootloader EFI binary. EFI Boot Guard release v0.15 contains required patches to sanitize and validate the bootloader environment prior to processing it in userspace. Its library and tools should be updated, so should programs statically linked against it. An update of the bootloader EFI executable is not required. The only way to prevent the issue with an unpatched EFI Boot Guard version is to avoid acces…
0
Attacker Value
Unknown
CVE-2023-26299
Disclosure Date: June 30, 2023 (last updated February 25, 2025)
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
0