Time-of-check Time-of-use Vulnerability in Dell BIOS
CVE-2023-28075
6.9MEDIUM
Summary
Dell BIOS is susceptible to a Time-of-check Time-of-use vulnerability, which allows local authenticated users with physical access to execute arbitrary code. By exploiting this flaw through a specifically timed Direct Memory Access (DMA) transaction during System Management Interrupt (SMI) events, attackers could gain unauthorized privileges. This poses a significant risk to system integrity and highlights the necessity for rigorous physical security measures.
Affected Version(s)
CPG BIOS All Versions
References
CVSS V3.1
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved