Integer Overflow in ARM Trusted Firmware Allows Unauthorized Memory Access
CVE-2017-9607
7HIGH
Summary
An integer overflow vulnerability exists in the BL1 Firmware Update Secure Monitor Call (FWU SMC) handling code of ARM Trusted Firmware prior to version 1.4. This flaw may enable attackers to bypass the bl1_plat_mem_check protection mechanism, allowing unauthorized writing of arbitrary data to secure memory. Exploitation of this vulnerability could lead to denial of service scenarios or other undisclosed impacts through the deployment of a specially crafted AArch32 image.
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved