Potential NULL Pointer Dereference Vulnerability in Intel UEFI Firmware May Allow Escalation of Privilege
CVE-2023-23904

6.1MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 September 2024

Summary

A null pointer dereference vulnerability in UEFI firmware for certain Intel processors can potentially allow a privileged user to escalate privileges through local access. This issue arises from improper handling of null pointers, enabling local attackers to bypass security controls. It is crucial for users and organizations utilizing affected Intel UEFI firmware to apply available mitigations advised by Intel to protect their systems against potential exploitation.

Affected Version(s)

UEFI firmware for some Intel(R) Processors See references

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.