cbcvebase.
CVE-2022-34401
published 2023-01-18

CVE-2022-34401: Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI…

PriorityP335high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
EPSS
0.17%
6.3th percentile
Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.

Affected

4 ranges
VendorProductVersion rangeFixed in
dellalienware_m15_a6_firmware< 1.4.31.4.3
dellalienware_m17_r5_firmware< 1.4.31.4.3
dellcpg_bios
dellg15_5525_firmware< 1.4.31.4.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.