Potential NULL Pointer Dereference Vulnerability in Intel UEFI Firmware May Allow Escalation of Privilege
CVE-2023-23904
6.1MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 16 September 2024
Summary
A null pointer dereference vulnerability in UEFI firmware for certain Intel processors can potentially allow a privileged user to escalate privileges through local access. This issue arises from improper handling of null pointers, enabling local attackers to bypass security controls. It is crucial for users and organizations utilizing affected Intel UEFI firmware to apply available mitigations advised by Intel to protect their systems against potential exploitation.
Affected Version(s)
UEFI firmware for some Intel(R) Processors See references
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved