Dell BIOS vulnerability allows arbitrary code execution with high privilege
CVE-2024-47238
6.7MEDIUM
Summary
The Dell Client Platform BIOS is affected by an input validation vulnerability in an externally developed component. This flaw may allow a highly privileged attacker with local access to exploit the vulnerability, potentially leading to arbitrary code execution on the affected system. Addressing this issue is vital for maintaining the integrity and security of the system's BIOS, as improper input handling could facilitate unauthorized actions and compromise sensitive data.
Affected Version(s)
Dell Client Platform BIOS < 1.29.0
Dell Client Platform BIOS < 1.19.0
Dell Client Platform BIOS < 1.25.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell Technologies would like to thank Eclypsium for reporting this issue.