Integer Overflow in ARM Trusted Firmware Allows Unauthorized Memory Access
CVE-2017-9607
7HIGH
What is CVE-2017-9607?
An integer overflow vulnerability exists in the BL1 Firmware Update Secure Monitor Call (FWU SMC) handling code of ARM Trusted Firmware prior to version 1.4. This flaw may enable attackers to bypass the bl1_plat_mem_check protection mechanism, allowing unauthorized writing of arbitrary data to secure memory. Exploitation of this vulnerability could lead to denial of service scenarios or other undisclosed impacts through the deployment of a specially crafted AArch32 image.