SMM Vulnerability Allows Privileged Attackers to Execute Arbitrary Code and Leak Information
CVE-2024-33657
7.8HIGH
What is CVE-2024-33657?
This vulnerability in AMI firmware relates to the System Management Mode (SMM) and affects certain firmware modules. It permits attackers with privileged access to execute arbitrary code, manipulate the stack memory, and leak sensitive information from the System Management RAM (SMRAM) to kernel space. Such exploits pose significant risks, including potential denial-of-service attacks, which could compromise system availability and integrity. Organizations utilizing affected versions of AMI firmware should prioritize applying patches and updates to mitigate these risks.
Affected Version(s)
AptioV BKS_5.0 <= 5.36