Memory Corruption in SMI Handler of HddPassword SMM Module Affects Huawei Matebook D16
CVE-2023-52547

7.8HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
28 May 2024

Summary

A memory corruption vulnerability exists within the System Management Interrupt (SMI) handler of the HddPassword System Management Mode (SMM) module in Huawei Matebook D16, specifically in model CREM-WXX9 with BIOS version v2.26. This issue could allow an attacker with malicious OS capabilities to alter data structures stored at the beginning of the System Management RAM (SMRAM). Exploitation of this vulnerability has the potential for unauthorized code execution in SMM, posing risks to system integrity and data security.

Affected Version(s)

CurieM-WFG9B OTA-CurieM-BIOS-2.29

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.